PT-2024-38012 · Cato · Cato Windows Sdp Client

Amberwolf

·

Published

2024-07-31

·

Updated

2024-08-27

·

CVE-2024-6973

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cato Windows SDP client versions prior to 5.10.34
Description The issue is related to Remote Code Execution and Improper Input Validation, allowing OS Command Injection via crafted URLs. This can potentially lead to malicious commands being executed on the affected system.
Recommendations For versions prior to 5.10.34, update to version 5.10.34 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted URLs that could exploit the Improper Input Validation vulnerability until a patch is applied.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-6973

Affected Products

Cato Windows Sdp Client