cve/2024/CVE-2024-7401.md
2025-09-29 16:08:36 +00:00

18 lines
829 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-7401](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7401)
![](https://img.shields.io/static/v1?label=Product&message=Netskope%20Client&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-287%20Improper%20Authentication&color=brighgreen)
### Description
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customers tenant and impersonate a user.
### POC
#### Reference
- https://quickskope.com/
#### Github
- https://github.com/tjnull/QuickSkope