Cisco doesn’t yet have a fix for a zero-day vulnerability in the Linux, MacOS, and Windows versions of its virtual private network (VPN) software, AnyConnect Secure Mobility Client.
While Cisco says it isn’t aware of any instances in which attackers have exploited the vulnerability, in a security advisory updated late Thursday, the vendor warned that a proof-of-concept exploit code is available, and this would make it significantly easier to take advantage of the flaw.
The high-severity bug, CVE-2020-3556, earned a CVSS score of 7.3 and is an arbitrary code execution vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client software. It’s due to a lack of authentication to the IPC listener, and attacker could exploit this vulnerability by sending crafted IPC messages to the AnyConnect client IPC listener. If exploited, an attacker could execute a malicious script via the targeted AnyConnect user.
Cisco has not released a patch for this vulnerability and says there are no workarounds. The vendor plans to fix the flaw in a future software release.
The security advisory credited Gerbert Roitburd from Secure Mobile Networking Lab in Darmstadt, Germany, with finding and reporting the vulnerability.
This zero-day VPN bug is the latest of about three-dozen high- and medium-severity vulnerabilities that Cisco disclosed over the last few days. Cisco released patches for all of the others. Twelve of these are high-severity flaws, and they affect Cisco WebEx, SD-WAN, and the Preboot eXecution Environment (PXE) boot loader for IOS XR software.
Comments