Cisco Fixes High-Severity Code Execution and VPN Hijacking Flaws
ID: e1fe4597-533d-53e3-a7d3-5a3b75344477
STIX ID: report--e1fe4597-533d-53e3-a7d3-5a3b75344477
Feed Name: HackRead
Cisco released security updates addressing critical and high-severity vulnerabilities in Cisco Secure Client — notably CVE-2024-20337 (CRLF injection, CVSS 8.2) that can enable remote script execution and theft of SAML tokens to hijack VPN sessions, and CVE-2024-20338 (authenticated local privilege escalation on Linux). The advisory also warns of unpatched remote code execution flaws in end-of-life Small Business wireless access points; Cisco recommends upgrading Secure Client to fixed versions (e.g., 5.1.2.42) and following security best practices, while noting no current evidence of exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
