Information disclosure in Cisco Systems, Inc products - CVE-2023-36673

 

Information disclosure in Cisco Systems, Inc products - CVE-2023-36673

Published: August 9, 2023


Vulnerability identifier: #VU79273
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-36673
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Cisco Secure Client AnyConnect VPN for iOS
Cisco AnyConnect Secure Mobility Client for Linux
Cisco AnyConnect Secure Mobility Client for MacOS
Cisco AnyConnect Secure Mobility Client for Windows
Cisco Secure Client for Linux
Cisco Secure Client for MacOS
Cisco Secure Client for Windows
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected application is vulnerable to ServerIP attacks. A remote attacker on the local network can manipulate routing exceptions and cause VPN clients to leak traffic outside the protected VPN tunnel.


Remediation

Install updates from vendor's website.

External links