6.5

CVE-2024-20474

A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client.

 This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software.

 Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoSecure Client Version4.10.00093
CiscoSecure Client Version4.10.01075
CiscoSecure Client Version4.10.02086
CiscoSecure Client Version4.10.03104
CiscoSecure Client Version4.10.04065
CiscoSecure Client Version4.10.04071
CiscoSecure Client Version4.10.05085
CiscoSecure Client Version4.10.05095
CiscoSecure Client Version4.10.05111
CiscoSecure Client Version4.10.06079
CiscoSecure Client Version4.10.06090
CiscoSecure Client Version4.10.07061
CiscoSecure Client Version4.10.07062
CiscoSecure Client Version4.10.07073
CiscoSecure Client Version4.10.08025
CiscoSecure Client Version4.10.08029
CiscoSecure Client Version5.0.00238
CiscoSecure Client Version5.0.00529
CiscoSecure Client Version5.0.00556
CiscoSecure Client Version5.0.01242
CiscoSecure Client Version5.0.02075
CiscoSecure Client Version5.0.03072
CiscoSecure Client Version5.0.03076
CiscoSecure Client Version5.0.04032
CiscoSecure Client Version5.0.05040
CiscoSecure Client Version5.1.0.136
CiscoSecure Client Version5.1.1.42
CiscoSecure Client Version5.1.2.42
CiscoSecure Client Version5.1.3.62
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.288
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
psirt@cisco.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-191 Integer Underflow (Wrap or Wraparound)

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.