Vulnerabilities
Vulnerable Software
Netskope:  >> Netskope  >> 100  Security Vulnerabilities
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customer’s tenant and impersonate a user.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-08-26
Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service. 
CVSS Score
6.6
EPSS Score
0.001
Published
2023-11-06


Contact Us

Shodan ® - All rights reserved