Show filters
160 Total Results
Displaying 31-40 of 160
Sort by:
Attacker Value
Unknown
CVE-2023-20241
Disclosure Date: November 22, 2023 (last updated December 01, 2023)
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system.
These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnerabilities by logging in to an affected device at the same time that another user is accessing Cisco Secure Client on the same system, and then sending crafted packets to a port on that local host. A successful exploit could allow the attacker to crash the VPN Agent service, causing it to be unavailable to all users of the system. To exploit these vulnerabilities, the attacker must have valid credentials on a multi-user system.
0
Attacker Value
Unknown
CVE-2023-20240
Disclosure Date: November 22, 2023 (last updated December 02, 2023)
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnerabilities by logging in to an affected device at the same time that another user is accessing Cisco Secure Client on the same system, and then sending crafted packets to a port on that local host. A successful exploit could allow the attacker to crash the VPN Agent service, causing it to be unavailable to all users of the system. To exploit these vulnerabilities, the attacker must have valid credentials on a multi-user system.
0
Attacker Value
Unknown
CVE-2023-41718
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
0
Attacker Value
Unknown
CVE-2023-38544
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
0
Attacker Value
Unknown
CVE-2023-38543
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
0
Attacker Value
Unknown
CVE-2023-38043
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.
0
Attacker Value
Unknown
CVE-2023-35080
Disclosure Date: November 15, 2023 (last updated November 23, 2023)
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.
0
Attacker Value
Unknown
CVE-2023-38041
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.
0
Attacker Value
Unknown
CVE-2023-24492
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
0
Attacker Value
Unknown
CVE-2023-24491
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
0