CVE-2022-2310
Estado: ModificadaCrítica (9.8)—
An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.20%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-290
- CWE-290
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-2310",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "trellixpsirt@trellix.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "trellixpsirt@trellix.com",
"affectedData": [
{
"vendor": "Skyhigh Security",
"product": "Skyhigh Secure Web Gateway (SWG)",
"versions": [
{
"status": "affected",
"version": "10.x",
"lessThan": "10.2.12",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.x",
"lessThan": "9.2.23",
"versionType": "custom"
},
{
"status": "affected",
"version": "8.x",
"lessThan": "8.2.28",
"versionType": "custom"
},
{
"status": "affected",
"version": "Controlled 11.x",
"lessThan": "11.2.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-07-27T10:15:08.280",
"references": [
{
"url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10384&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US",
"tags": [
"Vendor Advisory"
],
"source": "trellixpsirt@trellix.com"
},
{
"url": "https://kcm.trellix.com/corporate/index?page=content&id=SB10384&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "trellixpsirt@trellix.com",
"description": [
{
"lang": "en",
"value": "CWE-290"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-290"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG."
},
{
"lang": "es",
"value": "Una vulnerabilidad de omisión de autenticación en Skyhigh SWG en las versiones principales 10.x anteriores a 10.2.12, 9.x anteriores a 9.2.23, 8.x anteriores a 8.2.28 y la versión controlada 11.x anteriores a 11.2.1, permite a un atacante remoto omitir la autenticación en la Interfaz de Usuario de administración. Esto es posible debido a que el SWG ha incluido incorrectamente en su lista blanca los métodos de omisión de la autenticación y ha usado una contraseña criptográfica débil. Esto puede conllevar a que el atacante entre en la interfaz de administración del SWG, sin credenciales válidas, como super usuario con control total sobre el SWG"
}
],
"lastModified": "2026-06-17T04:41:40.377",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73A222C2-0A68-453F-A336-AEE5FC3A2CA8",
"versionEndExcluding": "8.2.28",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16F667F1-11C1-4E70-8924-A103D827FCEF",
"versionEndExcluding": "9.2.23",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08DC52C1-4CDE-41B3-AFB4-9904B1D23349",
"versionEndExcluding": "10.2.12",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDD760BD-58E4-46CB-BC53-1E2FB065C23C",
"versionEndExcluding": "11.2.1",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "trellixpsirt@trellix.com"
}