Tag: VPN Hijacking

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client
News

Cisco Issues Patch for High-Severity VPN Hijacking Bug in Secure Client

To address a high-severity security weakness in its Secure Client software that could allow a threat actor to start a VPN session with the targeted user, Cisco has published updates. The networking equipment manufacturer stated that an unauthorized, remote attacker might execute a carriage return line feed (CRLF) injection attack against a user due to the vulnerability, which is listed as CVE-2024-20337 (CVSS score: 8.2). A threat actor could make use of this vulnerability, which results from inadequate validation of user-supplied input, to fool a user into clicking on a specially constructed link in the process of starting a VPN session. According to the company's advice, if the exploit is successful, the attacker might be able to run arbitrary script code in the browser read mo...