CVE-2023-43976: Race Condition
Published Oct 3, 2023
·Updated
An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.
Affected Software
1 affected component
CatoNetworks Cato Client Macos<5.4.0
Event History
Oct 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-43976.
2
What is the severity of CVE-2023-43976?
The severity of CVE-2023-43976 is high with a CVSS score of 8.1.
3
What software is affected by CVE-2023-43976?
Catonetworks Cato Client versions up to and excluding 5.4.0 on macOS are affected by CVE-2023-43976.
4
How can attackers exploit CVE-2023-43976?
Attackers can exploit CVE-2023-43976 to escalate privileges and win the race condition (TOCTOU) via the PrivilegedHelperTool component.
5
Are there any references for CVE-2023-43976?
Yes, you can find more information about CVE-2023-43976 at the following references: [Cato Networks](https://www.catonetworks.com) and [NS-Echo](https://www.ns-echo.com/posts/cve_2023_43976.html).