QID 379486
Date Published: 2024-03-11
QID 379486: Cisco Secure Client (formerly AnyConnect) Carriage Return Line Feed Injection Vulnerability (cisco-sa-secure-client-crlf-W43V4G7)
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user.
Affected Products
From 4.10.04065 prior to 4.10.08025
From 5.0 prior to 5.1.2.42
Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.
QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client using registry information.
A successful exploit could allow the attacker to execute arbitrary script code in the browser or access sensitive, browser-based information, including a valid SAML token.
Customers are advised to refer to cisco-sa-secure-client-crlf-W43V4G7 for more information.
- cisco-sa-secure-client-crlf-W43V4G7 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7
CVEs related to QID 379486
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-secure-client-crlf-W43V4G7 |
|