CVE-2024-20474

A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client.

 This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software.

 Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.
Wrap or Wraparound
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
ciscoCNA
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
ciscoanyconnect_secure_mobility_client
4.9.00086
ciscoanyconnect_secure_mobility_client
4.9.01095
ciscoanyconnect_secure_mobility_client
4.9.02028
ciscoanyconnect_secure_mobility_client
4.9.03047
ciscoanyconnect_secure_mobility_client
4.9.03049
ciscoanyconnect_secure_mobility_client
4.9.04043
ciscoanyconnect_secure_mobility_client
4.9.04053
ciscoanyconnect_secure_mobility_client
4.9.05042
ciscoanyconnect_secure_mobility_client
4.9.06037
ciscosecure_client
4.10.00093
ciscosecure_client
4.10.01075
ciscosecure_client
4.10.02086
ciscosecure_client
4.10.03104
ciscosecure_client
4.10.04065
ciscosecure_client
4.10.04071
ciscosecure_client
4.10.05085
ciscosecure_client
4.10.05095
ciscosecure_client
4.10.05111
ciscosecure_client
4.10.06079
ciscosecure_client
4.10.06090
ciscosecure_client
4.10.07061
ciscosecure_client
4.10.07062
ciscosecure_client
4.10.07073
ciscosecure_client
4.10.08025
ciscosecure_client
4.10.08029
ciscosecure_client
5.0.00238
ciscosecure_client
5.0.00529
ciscosecure_client
5.0.00556
ciscosecure_client
5.0.01242
ciscosecure_client
5.0.02075
ciscosecure_client
5.0.03072
ciscosecure_client
5.0.03076
ciscosecure_client
5.0.04032
ciscosecure_client
5.0.05040
ciscosecure_client
5.1.0.136
ciscosecure_client
5.1.1.42
ciscosecure_client
5.1.2.42
ciscosecure_client
5.1.3.62
𝑥
= Vulnerable software versions