1 results (0.003 seconds)
CVSS: 7.3EPSS: 0%CPEs: 2EXPL: 0

CVE-2020-3556 – Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2020-3556
06 Nov 2020 — A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could exploit this vulnerability by sending crafted IPC messages to the AnyConnect client IPC listener. A successful exploit could allow an attacker to cause the targeted AnyConnect user to execute ... • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-ipc-KfQO9QhK • CWE-20: Improper Input Validation •