PT-2026-29240 · Cato Networks · Cato Networks Socket

CVE-2025-14213

·

Publicado

2026-03-31

·

Atualizado

2026-07-25

CVSS v4.0

8.3

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Cato Networks Socket versions prior to 25
Description An authenticated attacker with access to the Socket web interface (UI) can execute arbitrary operating system commands as the root user on the Socket’s internal system. The issue is a command injection. The affected component is the Socket web interface. The attacker needs to be authenticated to exploit this issue.
Recommendations Update Cato Networks Socket to version 25 or later.

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14213

Produtos afetados

Cato Networks Socket