CVE-2024-20337
published 2024-03-06CVE-2024-20337: A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line…
PriorityP264high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
29.91%
98.0th percentile
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user. Individual hosts and services behind the VPN headend would still need additional credentials for successful access.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
| cisco | cisco_secure_client | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attacker exploits CRLF injection in the SAML authentication process of Cisco Secure Client by persuading a user to click a crafted link while establishing a VPN session, enabling arbitrary script execution or SAML token theft. ↗
- →A stolen SAML token can be used to establish a remote access VPN session; monitor for anomalous VPN session establishments using SAML tokens, especially from unexpected sources or user agents. ↗
- →Track Cisco Bug ID CSCwi37512 for patch and detection guidance related to this CRLF injection vulnerability in Cisco Secure Client. ↗
- ·The vulnerability is in the SAML authentication process specifically; only Cisco Secure Client deployments using SAML-based VPN authentication are affected. ↗
- ·Even if an attacker successfully steals a SAML token and establishes a VPN session, individual hosts and services behind the VPN headend still require additional credentials — lateral movement is not automatic. ↗
- ·There are no workarounds available; remediation requires applying Cisco's software updates. ↗
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
vendor_cisco8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Client Carriage Return Line Feed Injection Vulnerability
vendor_cisco·2024-03-06·CVSS 8.2
CVE-2024-20337 [HIGH] CWE-93 Cisco Secure Client Carriage Return Line Feed Injection Vulnerability
Cisco Secure Client Carriage Return Line Feed Injection Vulnerability
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user. Individual hosts and services beh
Cisco
Cisco Secure Client Carriage Return Line Feed Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20337 Cisco Secure Client Carriage Return Line Feed Injection Vulnerability
CVE-2024-20337: Cisco Secure Client Carriage Return Line Feed Injection Vulnerability
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user. Individual hosts an
GHSA
GHSA-j296-jhq5-3x6c: A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return
ghsa_unreviewed·2024-03-06
CVE-2024-20337 [HIGH] CWE-93 GHSA-j296-jhq5-3x6c: A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user. Individual hosts and services behind the VPN headend would still need additional credentials for success
No detection rules found.
No public exploits indexed.
2024-03-06
Published