CVE-2024-20337 is a high-severity CRLF injection vulnerability in the SAML authentication process of Cisco Secure Client, affecting Apple, Cisco, Linux, and Microsoft platforms. An unauthenticated, remote attacker can exploit this by persuading a user to click a crafted link during VPN session establishment. This allows the attacker to execute arbitrary script code, access sensitive browser-based information including SAML tokens, and potentially establish a remote access VPN session with the user's privileges. While not actively exploited (KEV: No), its high CVSS score of 8.2 and mention in community discussions and media coverage indicate significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.10.04065, < 4.10.08025CPE matchmatch criteria | cpe:2.3:a:cisco:secure_client:*:*:*:*:*:*:*:* | ||
>= 5.0.00529, < 5.1.2.42CPE matchmatch criteria | cpe:2.3:a:cisco:secure_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.