Cato Networks
First CVE: Jul 31, 2024Active for: 2 years
9
CVEs Published
More CVEs Published than 25% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Cato Networks over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2024
23 months ago
Most Recent CVE
Jul 1, 2026
23 days ago
Top CVEs
All CVEs published by Cato Networks as a CNA, regardless of affected vendor or product.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12374MEDIUM Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a loc | Jul 1, 2026 | 6.4 | 29 | NO | NO |
CVE-2025-14213HIGH Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute a | Mar 31, 2026 | 8.3 | 27 | NO | NO |
CVE-2025-7012HIGH An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling. | Jul 13, 2025 | 8.6 | 26 | NO | NO |
CVE-2024-6975HIGH Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file.
This issue affects SDP Client before 5.10.34. | Jul 31, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-6973HIGH Remote Code Execution in Cato Windows SDP client via crafted URLs.
This issue affects Windows SDP Client before 5.10.34. | Jul 31, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-6978HIGH Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28. | Jul 31, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-6974HIGH Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34. | Jul 31, 2024 | 7.8 | 23 | NO | NO |
CVE-2025-3886HIGH An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component. | Apr 27, 2025 | 8.1 | 20 | NO | NO |
CVE-2024-6977MEDIUM A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack r | Jul 31, 2024 | 6.5 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA9 CVEs
22%
78%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (66.7%)
Network3 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low6 (66.7%)
High1 (11.1%)
None2 (22.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Cato Networks as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Cato Networks as a CNA — matched by CVE ID, not by organization name.