216.73.216.6

CVE-2025-0309

· Published 14/08/2025 05:15 · Modified 15/08/2025 13:15

Labels: CVE-2025-0309 2025-08-14CVE-2025-0309CWE-295[email protected]

Essential information

Published
14/08/2025 05:15
Modified
15/08/2025 13:15
Author
Creator
CVSS
6.0 MEDIUM (v3) 6.0 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope Client to connect to any other server with Public Signed CA TLS certificates and send specially crafted responses to elevate privileges.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
netskope / netskope client cpe:2.3:a:netskope:netskope_client:*:*:*:*:*:*:*:*

References