PT-2022-12247 · Netskope · Netskope Client

Ben O’Dea

+1

·

Published

2022-11-03

·

Updated

2023-10-25

·

CVE-2021-44862

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netskope client (affected versions not specified)
Description The issue allows an authenticated, local attacker to view sensitive information stored in NSClient logs, which should be restricted. This occurs because the sensitive information is not masked or scrubbed before being written to the logs. A malicious user can exploit this to download data and impersonate another user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2021-44862

Affected Products

Netskope Client