
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2021-1450) was discovered in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client. The vulnerability was first published on February 24, 2021, and affects all releases earlier than 4.10.00093 of AnyConnect Secure Mobility Client for Windows, MacOS, and Linux platforms. The vulnerability does not affect AnyConnect Secure Mobility Client for Apple iOS, Android, and Universal Windows platforms (Cisco Advisory).
The vulnerability stems from insufficient validation of user-supplied input in the IPC channel. It has been assigned a CVSS base score of 5.5 (Medium severity) with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X. The vulnerability is classified under CWE-20 (Cisco Advisory).
A successful exploitation of this vulnerability could allow an authenticated, local attacker to cause a denial of service (DoS) condition by stopping the AnyConnect process on an affected device. However, it's important to note that the affected process will automatically restart without requiring user or administrator intervention (Cisco Advisory).
The vulnerability requires local access and valid credentials on the target device for exploitation. An attacker could exploit this vulnerability by sending one or more crafted IPC messages to the AnyConnect process. The Cisco PSIRT has acknowledged the existence of proof-of-concept exploit code but is not aware of any malicious use of this vulnerability in the wild (Cisco Advisory).
Cisco has released software updates to address this vulnerability in version 4.10.00093 and later releases of the AnyConnect Secure Mobility Client. No workarounds are available for this vulnerability. Customers are advised to upgrade to a fixed release and regularly consult Cisco Security Advisories for complete upgrade solutions (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."