Cato Windows SDP 客户端在版本 6.12.6 之前存在任意文件披露漏洞。由于不当的文件路径验证以及缺失的 TLS 证书强制机制,低权限本地用户可以诱使以 Local System 身份运行的 Windows 服务读取并披露任意本地文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cato Networks | SDP Client | 0 ~ 6.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet