PT-2024-38016 · Cato Networks · Cato Networks Sdp Client

·

CVE-2024-6978

·

Published

2024-07-31

·

Updated

2024-08-27

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cato Networks SDP Client versions prior to 5.10.28
Description The issue affects Cato Networks SDP Client on Windows, where local root certificates can be installed by low-privileged users, and there is an Improper Input Validation vulnerability that allows Command Injection.
Recommendations For versions prior to 5.10.28, update to version 5.10.28 or later to resolve the issue. As a temporary workaround, consider restricting access to certificate installation and input validation functions to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6978

Affected Products

Cato Networks Sdp Client