Man-in-the-Middle Vulnerability in Netskope Client Affecting Insider Security
CVE-2024-7402

7HIGH

Key Information:

Vendor

Netskope

Vendor
CVE Published:
14 August 2025

What is CVE-2024-7402?

Netskope has identified a vulnerability in the Netskope Client that allows a malicious insider to exploit the communication channel via Man-in-the-Middle techniques. This vulnerability can lead to unauthorized alteration of the Netskope Client configuration or potentially disabling the agent completely. Exploitation requires administrative access to the affected machine, which strengthens the need for robust internal security measures to mitigate such threats.

Affected Version(s)

Netskope Client 0 < 123.0.16, 126.0.9, 129.0.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sander de Wit
.
CVE-2024-7402 : Man-in-the-Middle Vulnerability in Netskope Client Affecting Insider Security