cbcvebase.
CVE-2024-20337
published 2024-03-06

CVE-2024-20337: A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line…

PriorityP264high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
29.91%
98.0th percentile
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link while establishing a VPN session. A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token. The attacker could then use the token to establish a remote access VPN session with the privileges of the affected user. Individual hosts and services behind the VPN headend would still need additional credentials for successful access.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client
ciscocisco_secure_client

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker exploits CRLF injection in the SAML authentication process of Cisco Secure Client by persuading a user to click a crafted link while establishing a VPN session, enabling arbitrary script execution or SAML token theft.
  • A stolen SAML token can be used to establish a remote access VPN session; monitor for anomalous VPN session establishments using SAML tokens, especially from unexpected sources or user agents.
  • Track Cisco Bug ID CSCwi37512 for patch and detection guidance related to this CRLF injection vulnerability in Cisco Secure Client.
  • ·The vulnerability is in the SAML authentication process specifically; only Cisco Secure Client deployments using SAML-based VPN authentication are affected.
  • ·Even if an attacker successfully steals a SAML token and establishes a VPN session, individual hosts and services behind the VPN headend still require additional credentials — lateral movement is not automatic.
  • ·There are no workarounds available; remediation requires applying Cisco's software updates.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
vendor_cisco8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.