CVE-2024-6977
Cato Networks Windows SDP Client Sensitive data in trace logs can lead to account takeover
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
31 Jul 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
Cato Networks · SDP ClientWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →