QID 379481
Date Published: 2024-03-14
QID 379481: Cisco Secure Client (formerly AnyConnect) Privilege Escalation Vulnerability (cisco-sa-secure-privesc-sYxQO6ds)
A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device.
Affected Products
Cisco Secure Client for Linux prior to 5.1.2.42
QID Detection Logic (Authenticated):
This checks for vulnerable version of Cisco Secure Client
A successful exploit could allow the attacker to execute arbitrary code on an affected device with root privileges
Solution
Customers are advised to refer to cisco-sa-secure-privesc-sYxQO6ds for more information.
Vendor References
- cisco-sa-secure-privesc-sYxQO6ds -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-privesc-sYxQO6ds
CVEs related to QID 379481
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-secure-privesc-sYxQO6ds |
|