CVE-2024-7401: Client Enrollment Process Bypass
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customer’s tenant and impersonate a user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7401?
CVE-2024-7401 is considered a critical vulnerability due to the use of a static authentication token that cannot be rotated or revoked.
How do I fix CVE-2024-7401?
To fix CVE-2024-7401, organizations should update their Netskope Client to the latest version that addresses this vulnerability.
What impact does CVE-2024-7401 have on security?
CVE-2024-7401 allows an attacker to potentially gain unauthorized access to the Netskope Client by exploiting the static token during enrollment.
Is CVE-2024-7401 being actively exploited?
As of now, there are reports suggesting that CVE-2024-7401 is being actively exploited in the wild.
What should I do if I suspect exposure due to CVE-2024-7401?
If you suspect exposure due to CVE-2024-7401, you should immediately revoke all potentially compromised tokens and update to a patched version of the Netskope Client.