{"record":"Cato Networks evidence record","url":"https://nexalign.io/vendors/cato-networks","vendor":{"slug":"cato-networks","name":"Cato Networks","domain":"catonetworks.com","category":"network","categoryLabel":"Network security"},"lastChecked":"2026-07-18T04:17:38.573Z","coverage":{"earliest":"2022-06-08T09:41:17.221Z","latest":"2026-07-18T04:17:38.573Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":34,"kindsOfSource":6,"attributedAdvisories":9,"knownExploited":0,"registerEntriesNotAttributable":11,"practitionerThreads":0,"independentItems":6,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":11,"latest":"2026-05-15T10:00:53.938Z"},{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":9,"latest":"2026-07-01T14:07:28.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":2,"latest":"2026-03-31T12:16:26.813Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":9,"latest":"2026-07-18T04:17:38.573Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":2,"latest":"2026-03-01T16:27:53.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":1,"latest":"2026-02-15T10:50:18.000Z"}],"advisories":{"shown":6,"total":9,"truncated":true,"items":[{"id":"CVE-2026-12374","description":"Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local…","severity":"medium","cvss":6.4,"knownExploited":false,"date":"2026-07-01T14:07:28.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41001"]},{"id":"CVE-2025-14213","description":"Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary…","severity":"high","cvss":8.3,"knownExploited":false,"date":"2026-03-31T12:16:26.813Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-14213","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209145"]},{"id":"CVE-2025-7012","description":"An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.","severity":"high","cvss":8.6,"knownExploited":false,"date":"2025-07-13T08:15:22.910Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-7012","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21253"]},{"id":"CVE-2025-3886","description":"An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.","severity":"medium","cvss":5.7,"knownExploited":false,"date":"2025-04-27T10:41:17.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12448"]},{"id":"CVE-2024-6978","description":"Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.","severity":"medium","cvss":5.6,"knownExploited":false,"date":"2024-07-31T16:56:16.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47960"]},{"id":"CVE-2024-6977","description":"A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover.","severity":"medium","cvss":6.5,"knownExploited":false,"date":"2024-07-31T16:56:06.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47959"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":5,"total":6,"truncated":true,"items":[{"title":"Cato Networks Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/security-service-edge/vendor/cato-networks","date":null},{"title":"Cato Networks - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Cato_Networks","date":null},{"title":"What is your primary use case for Cato Networks?","host":"peerspot.com","url":"https://www.peerspot.com/questions/what-is-your-primary-use-case-for-cato-networks","date":null},{"title":"Cato Networks unveils modular adoption model for SASE platform | Computer Weekly","host":"computerweekly.com","url":"https://www.computerweekly.com/news/366640937/Cato-Networks-unveils-modular-adoption-model-for-SASE-platform","date":null},{"title":"Cato Networks Managed Network Services Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/cato-networks-managed-network-services","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 11 register entries mention Cato Networks without naming a product of Cato Networks as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Cato Networks was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}