Cisco Discloses AnyConnect VPN Zero-day, Exploit Code Available

Cisco Discloses AnyConnect VPN Zero-day, Exploit Code Available

Cisco has disclosed today a zero-day vulnerability in the Cisco AnyConnect Secure Mobility Client software with proof-of-concept exploit code publicly available.

While security updates are not yet available for this arbitrary code execution vulnerability, Cisco is working on addressing the zero-day, with a fix coming in a future AnyConnect client release.

However, the Cisco AnyConnect Secure Mobility Client security flaw has not yet been exploited in the wild according to the Cisco Product Security Incident Response Team (PSIRT).

Devices with default configurations not vulnerable

The high severity vulnerability tracked as CVE-2020-3556 exists in the interprocess communication (IPC) channel of Cisco AnyConnect Client and it may allow authenticated and local attackers to execute malicious scripts via a targeted user.

Also Read: Letter of Consent MOM: Getting the Details Right

It affects all AnyConnect client versions for Windows, Linux, and macOS with vulnerable configurations — mobile iOS and Android clients are not impacted by this vulnerability.

“A vulnerable configuration requires both the Auto Update setting and Enable Scripting setting to be enabled,” Cisco explains. “Auto Update is enabled by default, and Enable Scripting is disabled by default.”

Successful exploitation also requires active AnyConnect sessions and valid credentials on the targeted device.

Mitigation available

Even though there are no workarounds available to address CVE-2020-3556, it can be mitigated by disabling the Auto Update feature.

The attack surface can also be drastically decreased by toggling off the Enable Scripting configuration setting on devices where it’s enabled.

The vulnerability was reported to Cisco by Gerbert Roitburd from Secure Mobile Networking Lab (TU Darmstadt).

Cisco today also fixed 11 other high severity and 23 medium severity security bugs in multiple products that could lead to denial of service or arbitrary code execution on vulnerable devices.

Cisco also fixed actively exploited flaws in several carrier-grade routers and the ASA/FTD firewall in September and July, respectively.

Also Read: A Look at the Risk Assessment Form Singapore Government Requires

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago