CVE-2024-20474

A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure

Severity
Medium 4.3
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.006
48.0th percentile
Discovered by
Third party
Vendor-published field
Published
Oct 23, 2024
Assigned by cisco

Description

A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software. Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.

Weakness: CWE-191

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Client (AnyConnect) VPN & Remote Access cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Secure Client

Vendor advisory

cisco-sa-csc-dos-XvPhM3bj

Cisco Secure Client Software Denial of Service Vulnerability

Cisco’s rating: Medium (advisory CVSS 4.3) · Published Oct 23, 2024

Bug ID: CSCwj99060

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?