Missing Authentication for Critical Function in Cisco Secure Client for Windows - CVE-2024-20391

 

Missing Authentication for Critical Function in Cisco Secure Client for Windows - CVE-2024-20391

Published: May 16, 2024


Vulnerability identifier: #VU89589
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20391
CWE-ID: CWE-306
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to a lack of authentication on a specific function in the Network Access Manager (NAM) module. An attacker with physical access can execute arbitrary code with SYSTEM privileges on the target device.


Affected software

Cisco Secure Client for Windows

How to mitigate CVE-2024-20391

Install updates from vendor's website.

Cisco Secure Client for Windows - update to 5.1.3.62

External References

Related Security Bulletins