CVE-2024-6973

HIGH

Cato Windows SDP Client < 5.10.34 - Remote Code Execution via Crafted URLs

Title source: llm
STIX 2.1

Description

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

Scores

CVSS v3 7.5
EPSS 0.0076
EPSS Percentile 50.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
catonetworks/cato_client < 5.10.34
Published Jul 31, 2024
Tracked Since Feb 18, 2026