#VU34083 Input validation error in Cisco AnyConnect Secure Mobility Client - CVE-2020-3435
Published: August 6, 2020 / Updated: September 28, 2020
Cisco AnyConnect Secure Mobility Client
Cisco Systems, Inc
Description
The vulnerability allows a local user to overwrite VPN profiles on the targt device.
The vulnerability exists due to insufficient validation of user-supplied input in the interprocess communication (IPC) channel. A local user can send a specially crafted IPC message to the AnyConnect process and modify VPN profile files.