CVE-2021-1258
MEDIUMCisco Anyconnect Secure Mobility Client < 4.9.03047 - Improper Privilege Management
Title source: ruleDescription
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit this vulnerability.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-fileread-PbHbgHMj
Third Party Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10382
Scores
CVSS v3
5.5
EPSS
0.0004
EPSS Percentile
13.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-269
CWE-264
Status
published
Products (3)
cisco/anyconnect_secure_mobility_client
< 4.9.03047 (2 CPE variants)
cisco/anyconnect_secure_mobility_client
< 4.9.03049
mcafee/agent_epolicy_orchestrator_extension
< 5.7.6
Published
Jan 13, 2021
Tracked Since
Feb 18, 2026