CVE-2019-1853Out-of-bounds Read in Cisco Anyconnect Secure Mobility Client

CWE-125Out-of-bounds Read4 documents4 sources
Severity
7.5HIGHNVD
CNA4.8
EPSS
0.6%
top 30.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 24

Description

A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by crafting HTTP traffic for the affected component to download and process. A successful exploit could allow the attacker to read sensitive information on the affected sy

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-g45c-cv5h-jw66: A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read2022-05-24
CVEList
Cisco AnyConnect Secure Mobility Client for Linux Out-of-Bounds Memory Read Vulnerability2019-05-16

📋Vendor Advisories

1
Cisco
Cisco AnyConnect Secure Mobility Client for Linux Out-of-Bounds Memory Read Vulnerability2019-05-15
CVE-2019-1853 — Out-of-bounds Read in Cisco | cvebase