To address a high-severity security weakness in its Secure Client software that could allow a threat actor to start a VPN session with the targeted user, Cisco has published updates.
The networking equipment manufacturer stated that an unauthorized, remote attacker might execute a carriage return line feed (CRLF) injection attack against a user due to the vulnerability, which is listed as CVE-2024-20337 (CVSS score: 8.2).
A threat actor could make use of this vulnerability, which results from inadequate validation of user-supplied input, to fool a user into clicking on a specially constructed link in the process of starting a VPN session.
According to the company’s advice, if the exploit is successful, the attacker might be able to run arbitrary script code in the browser read more Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
