CVE Database
/

CVE-2024-7401

Back to search

CVE-2024-7401

Published: Aug 26, 2024

Modified: Jul 23, 2025

PUBLISHED

Description

Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A malicious actor can use this token to enroll NSClient from a customer’s tenant and impersonate a user.

VendorProductVersions

Netskope

Netskope Client

unknown
All

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now