PT-2020-3145 · Cisco · Cisco Anyconnect Secure Mobility Client

Hou Jingyi

·

Published

2020-07-01

·

Updated

2025-06-24

·

CVE-2020-3432

CVSS v3.1

5.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client for Mac OS (affected versions not specified)
Description A vulnerability in the uninstaller component could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The issue is due to the incorrect handling of directory paths. An attacker could exploit this by creating a symbolic link (symlink) to a target file on a specific path. A successful exploit could allow the attacker to corrupt the contents of the file, potentially leading to a denial of service condition if the file is critical to the system. The attacker would need valid credentials on the system to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Link Following

Weakness Enumeration

Related Identifiers

BDU:2020-03439
CVE-2020-3432

Affected Products

Cisco Anyconnect Secure Mobility Client