PT-2020-4667 · Cisco · Cisco Anyconnect Secure Mobility Client

Antoine Goichot

·

Published

2020-11-04

·

Updated

2020-11-12

·

CVE-2020-27123

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client (affected versions not specified)
Description The issue is related to an exposed interprocess communication (IPC) function in the Cisco AnyConnect Secure Mobility Client. This could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device by sending a crafted IPC message to the AnyConnect process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05219
CVE-2020-27123

Affected Products

Cisco Anyconnect Secure Mobility Client