CVE-2019-1853

Description

A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by crafting HTTP traffic for the affected component to download and process. A successful exploit could allow the attacker to read sensitive information on the affected system.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.603

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2018-0229,CVE-2018-0334,CVE-2018-0373,CVE-2019-1853 are affected in Cisco AnyConnect Secure Mobility Client For Windows 4.6Windows
Vulnerabilities CVE-2019-1853 are affected in Any Connect (Microsoft Store) 4.6(2074)Windows
Cisco AnyConnect Secure Mobility Client for Linux Out-of-Bounds Memory Read Vulnerability For Cisco AnyConnect Secure Mobility ClientNCM
Out-of-bounds Read Vulnerability (CVE-2019-1853)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234