First published: Wed Nov 04 2020(Updated: )
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process on an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-file-read-LsvDD6Uh
Credit: Antoine Goichot PwC Luxembourg's Cybersecurity team
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AnyConnect Secure |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-anyconnect-file-read-LsvDD6Uh is classified as high due to the potential for file access by unauthorized users.
To mitigate cisco-sa-anyconnect-file-read-LsvDD6Uh, update to the latest version of Cisco AnyConnect Secure Mobility Client that contains the necessary security patches.
Cisco AnyConnect Secure Mobility Client for Windows users are affected by the cisco-sa-anyconnect-file-read-LsvDD6Uh vulnerability.
An authenticated, local attacker can potentially read any arbitrary files on the underlying operating system due to cisco-sa-anyconnect-file-read-LsvDD6Uh.
The vulnerability cisco-sa-anyconnect-file-read-LsvDD6Uh is caused by an exposed interprocess communication (IPC) channel within Cisco AnyConnect.