Get real-time updates on Telegram
CVE-2023-20178: anyconnect secure mobility client before 4.10.07061 (exclusive); +2 more affected products
CVE-2023-20178. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.05374 (percentile 0.92452), scored 2026-10-08.
Affected technology
anyconnect secure mobility client · before 4.10.07061 (exclusive)
cisco
secure client · before 5.0.02075 (exclusive)
cisco
Cisco Secure Client · 4.9.00086, 4.9.01095, 4.9.02028, 4.9.03047, 4.9.03049, 4.9.04043, 4.9.04053, 4.9.05042, 4.9.06037, 4.10.00093, 4.10.01075, 4.10.02086, 4.10.03104, 4.10.04065, 4.10.04071, 4.10.05085, 4.10.05095, 4.10.05111, 4.10.06079, 4.10.06090, 5.0.00238, 5.0.00529, 5.0.00556, 5.0.01242
Cisco
Component: Not specified by the source
Function: of
Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
A low-privileged, authenticated, local attacker could elevate privileges to those of SYSTEM. Vendor/CNA’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-276
- CCR priority
- 32.5 /100 (P4)
- CVSS 3.1
- 7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.05374 · percentile 0.92452 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2023-20178.html