8.8
CVE-2024-6975
- EPSS 0.27%
- Veröffentlicht 31.07.2024 17:15:11
- Zuletzt bearbeitet 27.08.2024 15:40:05
- Quelle 2505284f-8ffb-486c-bf60-e19c10
- CVE-Watchlists
- Unerledigt
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Catonetworks ≫ Cato Client SwPlatformwindows Version < 5.10.34
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.182 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| 2505284f-8ffb-486c-bf60-e19c1097a90b | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://support.catonetworks.com/hc/en-us/articles/19758025406621-CVE-2024-6975-Windows-SDP-Client-Local-Privilege-Escalation-via-openssl-configuration-file