Denial of Service Vulnerability in Cisco Secure Client Software
CVE-2023-20240
Summary
Multiple vulnerabilities in Cisco Secure Client Software can be exploited by an authenticated local attacker to cause a denial of service (DoS) on a system. These vulnerabilities stem from an out-of-bounds memory read. An attacker with valid credentials can log in to the device while another user is simultaneously accessing the Cisco Secure Client. By sending crafted packets to a local port, the attacker may crash the VPN Agent service, rendering it unavailable to all users of the system. This scenario highlights the importance of maintaining secure access control and monitoring user activity on multi-user systems.
Affected Version(s)
Cisco Secure Client 4.9.00086
Cisco Secure Client 4.9.01095
Cisco Secure Client 4.9.02028
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved