CVE-2019-1853

MEDIUM

Cisco AnyConnect Secure Mobility Client for Linux - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by crafting HTTP traffic for the affected component to download and process. A successful exploit could allow the attacker to read sensitive information on the affected system.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108364

Scores

CVSS v3 4.8
EPSS 0.0060
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
cisco/anyconnect_secure_mobility_client 4.6\(2074\)
Published May 16, 2019
Tracked Since Feb 18, 2026