Untrusted Search Path Vulnerability in Cato Networks SDP Client Allows Privilege Escalation
CVE-2024-6975

8.8HIGH

Key Information:

Vendor
CVE Published:
31 July 2024

What is CVE-2024-6975?

Cato Networks' SDP Client suffers from a local privilege escalation vulnerability due to a flaw in its OpenSSL configuration file. This security issue could allow an attacker with local access to the affected system to elevate their privileges, potentially leading to unauthorized access and manipulation of system resources. All versions of the SDP Client prior to 5.10.34 are impacted, warranting immediate attention for users and administrators to mitigate the associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SDP Client Windows 0 < 5.10.34

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AmberWolf
.