CVE-2020-3153: Cisco AnyConnect Secure
EPSS28.3%No. 1029 of 1739 in KEV
CVE year2020~2 yrs before listing
Same vendor in KEV100
Same product2
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | AnyConnect Secure |
| Name | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability |
| Added to KEV | 2022-10-24 |
| US federal due date | 2022-11-14 |
| Ransomware use | Known |
| CWE | CWE-427 |
CISA description
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2020-3433 | Cisco AnyConnect Secure | 2022-10-24 | 10.0% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco AnyConnect Secure vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24.