Vulnslist

find the latest Cisco vulnerabilities

Cisco AnyConnect Secure Mobility Client for Windows Denial of Service Vulnerability

cisco-sa-anyconnect-dos-hMhyDfb8 · Medium · Published · Updated

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to a specific folder on the system. A successful exploit could allow the attacker to crash the VPN Agent service when the affected application is launched, causing it to be unavailable to all users of the system. To exploit this vulnerability, the attacker must have valid credentials on a multiuser Windows system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dos-hMhyDfb8

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2021-1568
Cisco Bug IDsCSCvx09155
CVSS ScoreBase 5.5
Base 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco AnyConnect Secure Mobility Client, Cisco Secure Client

Related Products

Product CVE Evidence
Cisco Secure Client CVE-2021-1568 Cisco OpenVuln
Cisco AnyConnect Secure Mobility Client CVE-2021-1568 Cisco OpenVuln