logo

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client

ID: cb6a7d34-5558-52b3-8e6b-2c74087394be

STIX ID: report--cb6a7d34-5558-52b3-8e6b-2c74087394be

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco released patches for two high-severity Secure Client vulnerabilities: CVE-2024-20337 (CRLF injection, CVSS 8.2) that can enable an unauthenticated attacker to execute script or steal a SAML token and establish a remote VPN session as the user, and CVE-2024-20338 (CVSS 7.3) allowing local privilege escalation on Linux; fixes and affected versions are listed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.