CVE-2013-1172

Description

The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153.

Risk Information

Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.082

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.0Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.1Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.2Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.2.128Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.2.133Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.2.136Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.2.140Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.3Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.3.185Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.3.2016Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.3.254Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.4.0202Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.4.1012Windows
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 2.5Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.0Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.1Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.128Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.133Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.136Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.140Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3.185Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3.2016Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3.254Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.4.0202Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.4.1012Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5Windows
Vulnerabilities CVE-2011-2040,CVE-2013-1172,CVE-2013-1173,CVE-2013-5559 are affected in Any Connect (Microsoft Store) 2.5.1025Windows
Vulnerabilities CVE-2011-2040,CVE-2013-1172,CVE-2013-1173,CVE-2013-5559 are affected in Any Connect (Microsoft Store) 2.5.2001Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2006Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2010Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2011Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2014Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2017Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2018Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.2019Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.0629Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.07059Windows
Vulnerabilities CVE-2012-2498,CVE-2013-1172,CVE-2013-1173 are affected in Any Connect (Microsoft Store) 3.0.08066Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.1.0Windows
Vulnerabilities CVE-2012-3088,CVE-2013-1172,CVE-2013-1173 are affected in Any Connect (Microsoft Store) 3.2.0Windows
Vulnerabilities CVE-2013-1130,CVE-2013-1172,CVE-2013-1173 are affected in Any Connect (Microsoft Store) -Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.0217Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.3041Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.3046Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.3051Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.3054Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5.3055Windows
Vulnerabilities CVE-2013-1172,CVE-2013-1173,CVE-2013-5559 are affected in Any Connect (Microsoft Store) 2.5.6005Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.1047Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.2052Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.3050Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.3054Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.4235Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.5075Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.5080Windows
Vulnerabilities CVE-2013-1172,CVE-2013-1173 are affected in Any Connect (Microsoft Store) 3.1.00495Windows
Cisco Host Scan Component of AnyConnect Secure Mobility and Secure Desktop Privilege Elevation Vulnerability For Cisco AnyConnect Secure Mobility ClientNCM
Improper Input Validation Vulnerability (CVE-2013-1172)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)
PATCH-332488Cisco AnyConnect Secure Mobility Client (4.10.07073)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234