AmberWolf Research
  • Home
  • Blog
  • Disclosure Policy
  • Main Site
to navigate to select ESC to close

Showing posts from Vulnerability Disclosure

  • Home
  • /   Tags
  • /   Vulnerability disclosure
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 26 Nov, 2024
    • Vulnerability Disclosure
    • Palo Alto
    • NachoVPN
    • GlobalProtect
    • VPN

Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)

Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 26 Nov, 2024
    • Vulnerability Disclosure

SonicWall NetExtender for Windows - RCE as SYSTEM via EPC Client Update (CVE-2024-29014)

SonicWall NetExtender for Windows - RCE as SYSTEM via EPC Client Update (CVE-2024-29014)

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

AmberWolf Uncovers Critical Vulnerabilities in Cato Client

As part of a recent client engagement, we conducted a product assessment of the Cato Client. During this assessment, we discovered significant …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

Cato Client - Account Takeover Via Sensitive Log Data (CVE-2024-6977)

The Cato Client was found to store authentication data within the trace logs generated by the desktop client during SSO authentication.

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

Cato SSO - Open Redirect Leading to Config Theft

The web service used during the Cato SSO authentication flow was found to contain an Open Redirect issue, which could allow a remote attacker to …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

Remote Code Execution via Crafted URLs (CVE-2024-6973)

The Cato Client suffers from a Remote Code Execution vulnerability which could be triggered via a URL handler, or via requests to the local webserver.

Read Article
  • Main Site
  • Privacy

Copyright AmberWolf 2024