QID 316883

Date Published: 2021-04-19

QID 316883: Cisco AnyConnect Secure Mobility Client Denial of Service Vulnerability(cisco-sa-anyconnect-dos-55AYyxYr)

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client
could allow an authenticated, local attacker to cause a
denial of service (DoS) condition on an affected device.
To exploit this vulnerability, the attacker would need to have
valid credentials on the device.

Affected Products
This vulnerability has affected all versions of the following products:
Cisco AnyConnect Secure Mobility Client for Windows
Cisco AnyConnect Secure Mobility Client for MacOS
Cisco AnyConnect Secure Mobility Client for Linux

QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client.

A successful exploit could allow the attacker to stop the AnyConnect process, causing a DoS condition on the device.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution

    Customers are advised to refer to cisco-sa-anyconnect-dos-55AYyxYr for more information.

    CVEs related to QID 316883

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-anyconnect-dos-55AYyxYr URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dos-55AYyxYr