PT-2024-38013 · Cato Networks · Cato Networks Sdp Client

Amberwolf

·

Published

2024-07-31

·

Updated

2024-08-27

·

CVE-2024-6974

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cato Networks SDP Client versions prior to 5.10.34
Description The issue affects the Cato Networks SDP Client on Windows, allowing for local privilege escalation due to an untrusted search path and incorrect default permissions.
Recommendations For versions prior to 5.10.34, update to version 5.10.34 or later to resolve the issue.

Exploit

Fix

Untrusted Search Path

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-6974

Affected Products

Cato Networks Sdp Client