cve/2024/CVE-2024-7401.md
2025-09-29 21:09:30 +02:00

882 B
Raw Permalink Blame History

CVE-2024-7401

Description

Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customers tenant and impersonate a user.

POC

Reference

Github