Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20338

Опубликовано: 06 мар. 2024
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device.

This vulnerability is due to the use of an uncontrolled search path element. An attacker could exploit this vulnerability by copying a malicious library file to a specific directory in the filesystem and persuading an administrator to restart a specific process. A successful exploit could allow the attacker to execute arbitrary code on an affected device with root privileges.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:cisco:secure_client:*:*:*:*:*:*:*:*
Версия до 5.1.2.42 (исключая)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

EPSS

Процентиль: 30%
0.00114
Низкий

7.3 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.3
github
почти 2 года назад

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. An attacker could exploit this vulnerability by copying a malicious library file to a specific directory in the filesystem and persuading an administrator to restart a specific process. A successful exploit could allow the attacker to execute arbitrary code on an affected device with root privileges.

CVSS3: 7.3
fstec
почти 2 года назад

Уязвимость модуля ISE Posture (System Scan) средства обеспечения безопасности конечных точек Cisco Secure Client (ранее Cisco AnyConnect Secure Mobility Client), позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 30%
0.00114
Низкий

7.3 High

CVSS3

Дефекты

CWE-427