logo

Cisco Fixes High-Severity Code Execution and VPN Hijacking Flaws

ID: e1fe4597-533d-53e3-a7d3-5a3b75344477

STIX ID: report--e1fe4597-533d-53e3-a7d3-5a3b75344477

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-03-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Cisco released security updates addressing critical and high-severity vulnerabilities in Cisco Secure Client — notably CVE-2024-20337 (CRLF injection, CVSS 8.2) that can enable remote script execution and theft of SAML tokens to hijack VPN sessions, and CVE-2024-20338 (authenticated local privilege escalation on Linux). The advisory also warns of unpatched remote code execution flaws in end-of-life Small Business wireless access points; Cisco recommends upgrading Secure Client to fixed versions (e.g., 5.1.2.42) and following security best practices, while noting no current evidence of exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.