Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-20391

Опубликовано: 15 мая 2024
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM.

This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:cisco:secure_client:*:*:*:*:*:*:*:*
Версия до 5.1.3.62 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00355
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 6.8
github
больше 1 года назад

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.

CVSS3: 6.8
fstec
больше 1 года назад

Уязвимость модуля Network Access Manager (NAM) средства обеспечения безопасности конечных точек Cisco Secure Client (ранее Cisco AnyConnect Secure Mobility Client), позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 57%
0.00355
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-306