Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-20474


A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software. Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.


Published

2024-10-23T18:15:11.517

Last Modified

2024-11-01T18:14:56.790

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-191
  • Type: Primary
    CWE-191

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco anyconnect_secure_mobility_client 4.9.00086 Yes
Application cisco anyconnect_secure_mobility_client 4.9.01095 Yes
Application cisco anyconnect_secure_mobility_client 4.9.02028 Yes
Application cisco anyconnect_secure_mobility_client 4.9.03047 Yes
Application cisco anyconnect_secure_mobility_client 4.9.03049 Yes
Application cisco anyconnect_secure_mobility_client 4.9.04043 Yes
Application cisco anyconnect_secure_mobility_client 4.9.04053 Yes
Application cisco anyconnect_secure_mobility_client 4.9.05042 Yes
Application cisco anyconnect_secure_mobility_client 4.9.06037 Yes
Application cisco secure_client 4.10.00093 Yes
Application cisco secure_client 4.10.01075 Yes
Application cisco secure_client 4.10.02086 Yes
Application cisco secure_client 4.10.03104 Yes
Application cisco secure_client 4.10.04065 Yes
Application cisco secure_client 4.10.04071 Yes
Application cisco secure_client 4.10.05085 Yes
Application cisco secure_client 4.10.05095 Yes
Application cisco secure_client 4.10.05111 Yes
Application cisco secure_client 4.10.06079 Yes
Application cisco secure_client 4.10.06090 Yes
Application cisco secure_client 4.10.07061 Yes
Application cisco secure_client 4.10.07062 Yes
Application cisco secure_client 4.10.07073 Yes
Application cisco secure_client 4.10.08025 Yes
Application cisco secure_client 4.10.08029 Yes
Application cisco secure_client 5.0.00238 Yes
Application cisco secure_client 5.0.00529 Yes
Application cisco secure_client 5.0.00556 Yes
Application cisco secure_client 5.0.01242 Yes
Application cisco secure_client 5.0.02075 Yes
Application cisco secure_client 5.0.03072 Yes
Application cisco secure_client 5.0.03076 Yes
Application cisco secure_client 5.0.04032 Yes
Application cisco secure_client 5.0.05040 Yes
Application cisco secure_client 5.1.0.136 Yes
Application cisco secure_client 5.1.1.42 Yes
Application cisco secure_client 5.1.2.42 Yes
Application cisco secure_client 5.1.3.62 Yes

References