CVE-2025-3886

An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:catonetworks:cato_client:*:*:*:*:*:macos:*:*

History

12 May 2025, 19:08

Type Values Removed Values Added
CPE cpe:2.3:a:catonetworks:cato_client:*:*:*:*:*:macos:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
References () https://support.catonetworks.com/hc/en-us/articles/26903049677597-Security-Vulnerability-CVE-2025-3886-that-Impacts-macOS-Client-Versions-Lower-than-5-8 - () https://support.catonetworks.com/hc/en-us/articles/26903049677597-Security-Vulnerability-CVE-2025-3886-that-Impacts-macOS-Client-Versions-Lower-than-5-8 - Vendor Advisory
First Time Catonetworks cato Client
Catonetworks

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Un problema en CatoClient de CatoNetworks anterior a la versión v.5.8.0 permite a los atacantes escalar privilegios y lograr una condición de ejecución (TOCTOU) a través del componente PrivilegedHelperTool.

27 Apr 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-27 11:15

Updated : 2025-05-12 19:08


NVD link : CVE-2025-3886

Mitre link : CVE-2025-3886

CVE.ORG link : CVE-2025-3886


JSON object : View

Products Affected

catonetworks

  • cato_client
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')