CVE-2020-3432 Details
Description
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a symbolic link (symlink) to a target file on a specific path. A successful exploit could allow the attacker to corrupt the contents of the file. If the file is a critical systems file, the exploit could lead to a denial of service condition. To exploit this vulnerability, the attacker would need to have valid credentials on the system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
A vulnerability exists in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS, prior to version 4.9.00086. This vulnerability allows an authenticated, local attacker to corrupt the content of any file in the filesystem. The issue arises from improper handling of directory paths, enabling an attacker to create a symbolic link to a target file. Exploitation could lead to corruption of the file's contents, and if a critical system file is targeted, it could cause a denial-of-service condition.
Users can upgrade to Cisco AnyConnect Secure Mobility Client for Mac OS version 4.9.00086 or later to address this vulnerability. For guidance on software upgrades, consult the Cisco Security Vulnerability Policy or contact the Cisco Technical Assistance Center (TAC).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-mac-dos-36s2y3Lv | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco anyconnect secure mobility client | < 4.9.00086 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2025 | Initial Analysis | [email protected] |
| Feb 26, 2025 | CVE Modified | CISA-ADP |
| Feb 24, 2025 | CVE Modified | [email protected] |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 12, 2025 | CVE Modified | CISA-ADP |
| Feb 12, 2025 | New CVE Received | [email protected] |