Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client
ID: cb6a7d34-5558-52b3-8e6b-2c74087394be
STIX ID: report--cb6a7d34-5558-52b3-8e6b-2c74087394be
Feed Name: The Hacker News
Threat Score
Cisco released patches for two high-severity Secure Client vulnerabilities: CVE-2024-20337 (CRLF injection, CVSS 8.2) that can enable an unauthenticated attacker to execute script or steal a SAML token and establish a remote VPN session as the user, and CVE-2024-20338 (CVSS 7.3) allowing local privilege escalation on Linux; fixes and affected versions are listed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
