Exposed dangerous method or function in Cisco AnyConnect Secure Mobility Client - CVE-2020-27123

 

Exposed dangerous method or function in Cisco AnyConnect Secure Mobility Client - CVE-2020-27123

Published: November 5, 2020


Vulnerability identifier: #VU48150
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27123
CWE-ID: CWE-749
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to read arbitrary files on the target system.

The vulnerability exists due to an exposed interprocess communication (IPC) channel function. A local user can send a specially crafted IPC message to the AnyConnect process and read arbitrary files on the underlying operating system of the affected device.


Affected software

Cisco AnyConnect Secure Mobility Client

How to mitigate CVE-2020-27123

Install updates from vendor's website.

Cisco AnyConnect Secure Mobility Client - update to 4.9.03047

External References

Related Security Bulletins