Netskope PSIRT is the centralized process through which Netskope customers, security researchers, industry groups, government organizations, or vendors report potential Netskope security vulnerabilities.
The Netskope team manages the receipt, investigation and internal coordination of security vulnerability information related to all Netskope products, offerings and websites. This team then coordinates with each individual Netskope product and solution team to investigate, and if needed, identify the appropriate response plan. Maintaining communication between all involved parties, both internal and external, is a key component of Netskope’s vulnerability response process.
We strongly believe in responsible and coordinated disclosures of vulnerabilities that may affect the services we provide. Public disclosure of vulnerabilities is an essential part of the vulnerability disclosure process and is one of the many paths that lead to making software better and enables learnings that makes the security community better.
Security Advisory ID | Severity Rating | Fix Version | Fix Description |
---|---|---|---|
NSKPSA-2024-003 | Medium | Release 119 and above | Endpoint DLP double-fetch leading to heap-overflow |
NSKPSA-2024-001 | High | N/A | Netskope client enrollment bypass issue |
NSKPSA-2023-003 | Medium | Release 101 | Netskope NSClient is impacted by local privilege escalation vulnerability to terminate the NSClient |
NSKPSA-2023-002 | High | Release 100 | Local privilege escalation using log files in Netskope Client |
NSKPSA-2023-001 | High | Release 100 | Local privilege escalation vulnerability in Netskope Client |
NSKPSA-2022-001 | High | Release 92 | Sensitive information stored in NSClient logs |
NSKPSA-2021-002 | High | Release 89 | Local privilege escalation vulnerability in Netskope Client on macOS |
NSKPSA-2020-005 | Critical | Release 81 | Netskope Client Stack Buffer Overflow |
NSKPSA-2020-004 | Critical | Release 81 | Netskope Client Stack Buffer Overflow |
NSKPSA-2020-002 | High | Release 79 | Netskope Admin UI CSV Injection |
NSKPSA-2020-001 | High | Release 78 | Fix for Privilege Escalation Vulnerability Discovered in Netskope Windows Client |
At Netskope, we take our responsibility to protect our users’ information and the services we provide to them very seriously.
Linked below is our Vulnerability Disclosure Policy. The Vulnerability Disclosure Policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.