CVE-2021-1258

MEDIUM

Cisco Anyconnect Secure Mobility Client < 4.9.03047 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit this vulnerability.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269 CWE-264
Status published
Products (3)
cisco/anyconnect_secure_mobility_client < 4.9.03047 (2 CPE variants)
cisco/anyconnect_secure_mobility_client < 4.9.03049
mcafee/agent_epolicy_orchestrator_extension < 5.7.6
Published Jan 13, 2021
Tracked Since Feb 18, 2026