CVE-2013-5559
published 2013-11-04CVE-2013-5559: Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.03%
78.8th percentile
Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AnyConnect Secure Mobility Client VPNAPI COM Buffer Overflow Vulnerability
vendor_cisco·2013-11-04·CVSS 6.8
CVE-2013-5559 [MEDIUM] CWE-20 Cisco AnyConnect Secure Mobility Client VPNAPI COM Buffer Overflow Vulnerability
Cisco AnyConnect Secure Mobility Client VPNAPI COM Buffer Overflow Vulnerability
A vulnerability in the Active Template Library (ATL) framework used by a component of the Cisco AnyConnect Secure Mobility Client could allow an unauthenticated, remote attacker to execute arbitrary commands with the privilege of the user executing the web browser.
The vulnerability is due to insufficient input validation when the ATL framework is called by the VPNAPI COM module. An attacker could exploit this vulnerability by persuading the a user with the Cisco AnyConnect Secure Mobility Client to visit a crafted HTML page. An exploit could allow the attacker to create a buffer overflow condition and possibly execute arbitrary code. Arbitrary code injection is theoretical and has not been proven.
Note: Th
GHSA
GHSA-pqr5-xvxq-fp5h: Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2
ghsa_unreviewed·2022-05-17
CVE-2013-5559 [MEDIUM] CWE-119 GHSA-pqr5-xvxq-fp5h: Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2
Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-04
Published