This section can help answer various queries while enabling Secure Configuration Services in a Netskope tenant.
What does the vulnerability look like?
The vulnerability is about modifications in the Netskope Client configurations which are set by the tenant administrator.
When will Netskope have the fix for the issue?
Netskope will release a fix with version 129.0.0 where you can use Netskope Client version 123 (123.0.15), 126 (126.0.9), 129.0.0 or higher and the Secure Configuration Service option in the tenant UI to apply the fix.
Which version of the Netskope Client is vulnerable to this?
All versions of Netskope Client are vulnerable unless the Secure Configuration Service is enabled from the tenant UI. Netskope Client versions 123.0.0, 126.0.0, 129.0.0 and higher will support the fix.
To apply the fix, what should I do next?
To enable this fix:
-
Ensure that “Secure Enrollment” is enabled and Clients are deployed with Authentication token for the UPN mode (tokens are not required to be pushed in IDP and email invitation).
-
Ensure that supported Netskope Client versions 123.0.0 and above are deployed.
-
Enable Netskope Client Secure Configuration from tenant UI.
What is the impact of applying the fix on users with Netskope Client?
Refer to the following to see the impact:
-
Existing enrolled users with Netskope Client version 123.0.0 will not have any impact.
-
Initially, Netskope Client might give 405 error on config download after enabling the feature, but will automatically resolve the issue.
-
-
New user enrollments with Netskope Client version 123.0.0 and with Secure Enrollment and Netskope Client Secure Configuration for APIs will not have any impact.
-
Users with the Netskope Client version before 123.0.0 will see Config Download failed error with 405 code and will not be able to download the configurations.
-
Users will continue to steer the traffic, but new configurations will not be downloaded for the users.
-
How can I roll back the feature, if there are any issues in their environment?
If you encounter any issues, disabling the feature Netskope Client Secure Configuration will roll back to the previous workflow.
Is there a countermeasure available to fix the gap?
The only countermeasure available is preventing users from installing or adding third-party certificates in their machines Operating System trust store. This will prevent users from performing MITM and tampering with the configurations.
How were we exposed before this fix?
A user with admin privileges could have tampered with the configurations using MITM tools such as Burp or Fiddler or ZAP etc. The change in configuration can include but not limited to such as modifying the Allow disabling of Netskope Client, Disabling Steering hardening configuration, Disabling tamper proofing and so on.
How do I identify if the flaw is being exploited or abused in my environment?
Netskope lists the devices and status of the devices in the UI. The information is listed under Settings > Security Cloud Platform > Netskope Client > Devices.
Netskope provides APIv1 endpoints integrated into SIEM and SOAR tools to generate alerts based on the Client status on a machine.
The same information is also exposed via APIv1 endpoint. The end point is:
-
api/v1/clients
-
Status_v2 values meaning: 3-Disabled 2-Enabled 0-Uninstalled
Below are some of the indicators which can point to the abuse:
-
Configuration to prevent users from disabling the client, but the user has disabled the Client.
-
Configurations to prevent uninstallation of the client from endpoint, but user have removed the client.
-
Configuration for device classification and the user’s device is listed in a particular device classification section but the user is able to bypass that.
What happens if I enable Secure Configuration Service but I have a Client which is not on at least version?
All Client versions 123 (123.0.16), 126 (126.0.9), 129 or higher will function as expected. Clients which are not upgraded to at least those versions will not be able to download the configuration, and will not be able to enroll new users or download configurations correctly.
Do I need to re-enroll all our existing users?
No, the fix does not require re-enrollment of users.
Do we plan on making a public disclosure (CVE) here?
Yes, it will be disclosed as CVE-2024-7402.
Q. What happens if I am an API only user?
If a user is not using the Netskope Client, then ensure that they have the secure enrollment auth token enabled and enforced. Activating Secure Configuration will not change the user experience with the tenant, but they will be covered from the security gap, especially if they decide to use the Netskope Client at a later time.

