Back to search
CVE-2024-7401
Published: Aug 26, 2024
Modified: Jul 23, 2025
PUBLISHED
Description
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customer’s tenant and impersonate a user.
| Vendor | Product | Versions |
|---|---|---|
Netskope | Netskope Client | unknown All |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now