Thursday, March 6, 2025
HomeCiscoCisco has Fixed a six-month-Old Zero-day Vulnerability Found in the Cisco AnyConnect

Cisco has Fixed a six-month-Old Zero-day Vulnerability Found in the Cisco AnyConnect

Published on

SIEM as a Service

Follow Us on Google News

The Cisco Product Security Incident Response Team (PSIRT) has recently fixed a six-month-old zero-day vulnerability that is tracked as “CVE-2020-3556” in Cisco AnyConnect Security Client. 

This zero-day flaw allows any attackers to execute arbitrary code; so, the experts have strongly recommended all the users to update their client immediately.

AnyConnect is a VPN security client that was launched by Cisco, and the chief function of AnyConnect VPN is to expedite all its users (intending company employees) to work safely on any device. 

No matter where the user is, as it allows all its users to work as usual using the laptops, and mobile devices provided by the company. 

AnyConnect simplifies and secures the terminal access to provide the necessary security measures to guarantee the constant security of the company or organization.

However, in the AnyConnect Secure Mobility Client Software releases 4.10.00093, and later this six-month-old zero-day vulnerability has been addressed.

Flaw Profile

Here we have mentioned all the details of this six-month-old zero-day vulnerability:-

  • CVE ID: CVE-2020-3556
  • CWE ID: CWE-20
  • Advisory ID: cisco-sa-anyconnect-ipc-KfQO9QhK
  • Cisco Bug IDs: CSCvv30103
  • CVSS Score: 7.3
  • Severity: High

This zero-day vulnerability actually detected in the inter-process communication (IPC) channel of the Cisco AnyConnect Secure Mobility Client. And this vulnerability is caused by the lack of authentication of the IPC listener.

To exploit this flaw any threat actor can send a specially crafted IPC message to the AnyConnect client IPC listener and allow that attacker to trick the user into executing malicious scripts on the infected system.

Apart from this, the security analysts at Cisco affirmed that:-

  • On the laptops used by a single user, this flaw is not exploitable.
  • This flaw is not remotely exploitable.
  • This vulnerability is not a privilege elevation exploit.
  • This security flaw is rated as high severity, as this has the ability to exploit the configurations.

Vulnerable Products

  • AnyConnect Secure Mobility Client for Windows
  • AnyConnect Secure Mobility Client for macOS
  • AnyConnect Secure Mobility Client for Linux

Determine Vulnerability

Below we have mentioned the locations where you can check the presence of this flaw:-

  • Windows:<DriveLetter>:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\
  • macOS: /opt/cisco/anyconnect/
  • Linux: /opt/cisco/anyconnect/

Mitigation

As a security measure, the analysts have recommended all the users who cannot immediately install the security updates to turn off the Auto-Update feature.

Moreover, they have also urged users to disable the Enable Scripting configuration setting on the devices where this setting is enabled. As they claimed that by doing so will reduce the attack surface.

Apart from this, if anyone somehow won’t able to upgrade their older versions to the newer version with all the security fixes, for them to apply the recommended workarounds Cisco have also provided the detailed upgradation guide.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Apache Airflow Misconfigurations Leak Login Credentials to Hackers

A recent investigation into misconfigured Apache Airflow instances has uncovered critical vulnerabilities exposing login...

Two Cybercriminals Arrested for ATM Jackpotting Scheme

Federal authorities have unveiled details of a sophisticated cybercrime operation targeting financial institutions across...

Black Basta’s Notorious Tactics and Techniques Exposed in Leaked Intel

A significant leak of internal chat logs from the Black Basta ransomware group has...

7 Malicious Go Packages Target Linux & macOS to Deploy Stealthy Malware Loader

Security researchers at Socket have uncovered a sophisticated malware campaign targeting the Go ecosystem....

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Cisco Webex for BroadWorks Flaw Opens Door for Attackers to Access Credentials

Cisco Systems has disclosed a security vulnerability in its Webex for BroadWorks unified communications...

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March...

Cisco Nexus Vulnerability Allows Attackers to Inject Malicious Commands

Cisco Systems has issued a critical security advisory for a newly disclosed command injection...