PT-2021-5038 · Cisco · Cisco Anyconnect Secure Mobility Client

Jacob Griffith

·

Published

2021-11-03

·

Updated

2022-04-25

·

CVE-2021-40124

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client (affected versions not specified)
Description The issue is related to incorrect privilege assignment in the Network Access Manager module, which could allow an authenticated, local attacker to escalate privileges on an affected device. An attacker could exploit this by configuring a script to be executed before logon, potentially allowing the execution of arbitrary code with SYSTEM privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05808
CVE-2021-40124

Affected Products

Cisco Anyconnect Secure Mobility Client