CVE-2024-20474 is a denial-of-service vulnerability affecting Cisco Secure Client Software (formerly Cisco AnyConnect Secure Mobility Client) due to an integer underflow in its IKEv2 processing. An unauthenticated, remote attacker can exploit this by sending a crafted IKEv2 packet, causing the client software to crash. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network attack vector with low complexity and high impact on availability, requiring no user interaction. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.9.00086CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.00086:*:*:*:*:*:*:* | ||
4.9.01095CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.01095:*:*:*:*:*:*:* | ||
4.9.02028CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.02028:*:*:*:*:*:*:* | ||
4.9.03047CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.03047:*:*:*:*:*:*:* | ||
4.9.03049CPE matchmatch criteria | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.03049:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.