Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client
To address a high-severity security weakness in its Secure Client software that could allow a threat actor to start a VPN session with the targeted user, Cisco has published updates.
The networking equipment manufacturer stated that an unauthorized, remote attacker might execute a carriage return line feed (CRLF) injection attack against a user due to the vulnerability, which is listed as CVE-2024-20337 (CVSS score: 8.2).
A threat actor could make use of this vulnerability, which results from inadequate validation of user-supplied input, to fool a user into clicking on a specially constructed link in the process of starting a VPN session.
According to the company's advice, if the exploit is successful, the attacker might be able to run arbitrary script code in the browser read mo...

