A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.
History

Tue, 27 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Catonetworks
Catonetworks cato Client
CPEs cpe:2.3:a:catonetworks:cato_client:*:*:*:*:*:windows:*:*
Vendors & Products Catonetworks
Catonetworks cato Client

cve-icon MITRE

Status: PUBLISHED

Assigner: Cato

Published: 2024-07-31T16:56:06.000Z

Updated: 2024-07-31T17:08:09.827Z

Reserved: 2024-07-22T10:18:14.285Z

Link: CVE-2024-6977

cve-icon Vulnrichment

Updated: 2024-07-31T17:08:06.897Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-31T17:15:11.860

Modified: 2024-08-27T15:41:15.443

Link: CVE-2024-6977

cve-icon Redhat

No data.