Home Cisco CVE-2024-20337
Back to Cisco

CVE-2024-20337

Cisco Secure Client - SAML Authentication

Cisco CVSS 8.2 Updated March 16, 2026

Executive Risk Summary

"A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user, potentially leading to arbitrary script code execution or access to sensitive browser-based information. Successful exploitation could allow an attacker to establish a remote access VPN session with the privileges of the affected user."

Operational Audit Arsenal

Target Type Software Component
Target Asset SAML Authentication Module
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Moderate

Internal Work Notes

CVE-2024-20337: CRLF injection vulnerability in Cisco Secure Client SAML authentication, potentially allowing remote attackers to execute arbitrary script code or access sensitive information, requiring prompt patching and verification of VPN session security.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Cisco Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.