CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2023-20178: anyconnect secure mobility client before 4.10.07061 (exclusive); +2 more affected products

CVE-2023-20178. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.05374 (percentile 0.92452), scored 2026-10-08.

Affected technology

anyconnect secure mobility client · before 4.10.07061 (exclusive)
cisco

secure client · before 5.0.02075 (exclusive)
cisco

Cisco Secure Client · 4.9.00086, 4.9.01095, 4.9.02028, 4.9.03047, 4.9.03049, 4.9.04043, 4.9.04053, 4.9.05042, 4.9.06037, 4.10.00093, 4.10.01075, 4.10.02086, 4.10.03104, 4.10.04065, 4.10.04071, 4.10.05085, 4.10.05095, 4.10.05111, 4.10.06079, 4.10.06090, 5.0.00238, 5.0.00529, 5.0.00556, 5.0.01242
Cisco

Component: Not specified by the source
Function: of

Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · No user interaction required

Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

A low-privileged, authenticated, local attacker could elevate privileges to those of SYSTEM. Vendor/CNA’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-276
CCR priority
32.5 /100 (P4)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.05374 · percentile 0.92452 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2023-20178.html