← Back

CVE-2018-0373

nvd nist
Published: Jun 21, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a malicious request to the application. A successful exploit could allow the attacker to cause a DoS condition on the affected system. Cisco Bug IDs: CSCvj47654.

Affected (9)

1 product
Anyconnect Secure Mobility Client
Configuration A
9 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 4.5(1044)
Version 4.5(2033)
Version 4.5(2036)
Version 4.5(3040)
Version 4.5(4029)
Version 4.5(5030)
Version 4.5(58)
Version 4.6(1098)
Version 4.6(362)
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.