Home

Description

An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

PUBLISHED Reserved 2025-04-22 | Published 2025-04-27 | Updated 2025-04-28 | Assigner Cato




MEDIUM: 5.7CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/RE:L/U:Green

Problem types

CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Product status

Default status
unaffected

Any version before 5.8.0
affected

References

support.catonetworks.com/...S-Client-Versions-Lower-than-5-8

cve.org (CVE-2025-3886)

nvd.nist.gov (CVE-2025-3886)

Download JSON