Information disclosure in Cisco Systems, Inc products - CVE-2023-36672
Published: August 9, 2023
Vulnerability identifier: #VU79271
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-36672
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
Cisco Secure Client AnyConnect VPN for iOS
Cisco AnyConnect Secure Mobility Client for Linux
Cisco AnyConnect Secure Mobility Client for MacOS
Cisco AnyConnect Secure Mobility Client for Windows
Cisco Secure Client for Linux
Cisco Secure Client for MacOS
Cisco Secure Client for Windows
Cisco Secure Client AnyConnect VPN for iOS
Cisco AnyConnect Secure Mobility Client for Linux
Cisco AnyConnect Secure Mobility Client for MacOS
Cisco AnyConnect Secure Mobility Client for Windows
Cisco Secure Client for Linux
Cisco Secure Client for MacOS
Cisco Secure Client for Windows
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application is vulnerable to LocalNet attacks. A remote attacker on the local network can manipulate routing exceptions and cause VPN clients to leak traffic outside the protected VPN tunnel.
Remediation
Install updates from vendor's website.