PT-2020-3145 · Cisco · Cisco Anyconnect Secure Mobility Client

·

CVE-2020-3432

·

Published

2020-07-01

·

Updated

2025-06-24

CVSS v3.1

5.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client for Mac OS (affected versions not specified)
Description A vulnerability in the uninstaller component could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The issue is due to the incorrect handling of directory paths. An attacker could exploit this by creating a symbolic link (symlink) to a target file on a specific path. A successful exploit could allow the attacker to corrupt the contents of the file, potentially leading to a denial of service condition if the file is critical to the system. The attacker would need valid credentials on the system to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03439
CVE-2020-3432

Affected Products

Cisco Anyconnect Secure Mobility Client