Permissions, Privileges, and Access Controls in Cisco AnyConnect Secure Mobility Client - CVE-2021-1258

 

Permissions, Privileges, and Access Controls in Cisco AnyConnect Secure Mobility Client - CVE-2021-1258

Published: January 13, 2021 / Updated: January 14, 2021


Vulnerability identifier: #VU49540
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1258
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information on the system.

The vulnerability exists due to insufficient file permission restrictions in the upgrade component. A local user can send a specially crafted command from the local CLI to the application and read arbitrary files on the underlying OS of the affected device.


Affected software

Cisco AnyConnect Secure Mobility Client

How to mitigate CVE-2021-1258

Install updates from vendor's website.

Cisco AnyConnect Secure Mobility Client - addressed in versions 4.9.03047, 4.9.03049

External References

Related Security Bulletins