VYPR

CatoClient

by Cato Networks

CVEs (4)

  • CVE-2025-7012HigJul 13, 2025
    risk 0.56cvss epss 0.00

    An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.

  • CVE-2025-3886HigApr 27, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

  • CVE-2023-43976HigOct 3, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.

  • CVE-2026-12374MedJul 1, 2026
    risk 0.00cvss epss 0.00

    Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that…