CVE-2013-1173Improper Restriction of Operations within the Bounds of a Memory Buffer in Cisco Anyconnect Secure Mobility Client

Severity
6.6MEDIUMNVD
EPSS
0.1%
top 74.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateMay 17

Description

Heap-based buffer overflow in ciscod.exe in the Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14143.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 2.7 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w9fv-cx3x-h3pg: Heap-based buffer overflow in ciscod2022-05-17
CVEList
CVE-2013-1173: Heap-based buffer overflow in ciscod2013-04-11

📋Vendor Advisories

2
Cisco
Cisco Host Scan Component of AnyConnect Secure Mobility and Secure Desktop Heap Overflow Vulnerability2013-04-11
Red Hat
Kernel: net: af_key: initialize satype in key_notify_policy_flush2013-02-18
CVE-2013-1173 — Cisco vulnerability | cvebase