[subscribe_to_unlock_form]
Summary:
Cisco addressing two high-severity vulnerabilities in Secure Client, an enterprise VPN application with security and monitoring features.[/subscribe_to_unlock_form]
Summary:
Cisco addressing two high-severity vulnerabilities in Secure Client, an enterprise VPN application with security and monitoring features.[emaillocker id="1283"]
- CVE-2024-20337 - affects Linux, macOS, and Windows versions, enabling remote exploitation without authentication through carriage return line feed (CRLF) injection attacks. Attackers can execute arbitrary scripts in a victim's browser or access sensitive data, like SAML tokens, by tricking users into clicking crafted links during VPN sessions.
- The second vulnerability, CVE-2024-20338, impacts Secure Client for Linux, requiring authentication for exploitation which allows attackers to execute arbitrary code with root privileges by persuading administrators to restart a specific process after placing a malicious library file in a specific directory.
Recommendations:
- We strongly recommend you to update Cisco versions 4.10.08025 and 5.1.2.42.
References:
The following reports contain further technical details:
https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-in-vpn-product/
[/emaillocker]