We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-20337



Assignercisco
Reserved2023-11-08
Published2024-03-06
Updated2024-08-01

Description

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user. Individual hosts and services behind the VPN headend would still need additional credentials for successful access.



HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Product status

4.9.00086
affected

4.9.01095
affected

4.9.02028
affected

4.9.03047
affected

4.9.03049
affected

4.9.04043
affected

4.9.04053
affected

4.9.05042
affected

4.9.06037
affected

4.10.00093
affected

4.10.01075
affected

4.10.02086
affected

4.10.03104
affected

4.10.04065
affected

4.10.04071
affected

4.10.05085
affected

4.10.05095
affected

4.10.05111
affected

4.10.06079
affected

4.10.06090
affected

4.10.07061
affected

4.10.07062
affected

4.10.07073
affected

5.0.00238
affected

5.0.00529
affected

5.0.00556
affected

5.0.01242
affected

5.0.02075
affected

5.0.03072
affected

5.0.03076
affected

5.0.04032
affected

5.0.05040
affected

5.1.0.136
affected

5.1.1.42
affected

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7 (cisco-sa-secure-client-crlf-W43V4G7)

cve.org CVE-2024-20337

nvd.nist.gov CVE-2024-20337

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-20337
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.