Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-4118

18
FAUCET Score

CVE-2009-4118 describes a denial-of-service vulnerability in the Cisco VPN Client for Windows, specifically affecting versions prior to 5.0.06.0100. The flaw resides in the cvpnd service's StartServiceCtrlDispatcher function, which mishandles an error when cvpnd.exe is manually started while the service is already running. This local vulnerability has a low severity CVSS score of 2.1, indicating a low attack complexity and impact limited to service crashes and VPN connection loss. While an ExploitDB entry (EDB-10190) exists, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2.0CPE matchmatch criteria
cpe:2.3:a:cisco:vpn_client:2.0:*:windows:*:*:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:a:cisco:vpn_client:3.0:*:windows:*:*:*:*:*
3.0.5CPE matchmatch criteria
cpe:2.3:a:cisco:vpn_client:3.0.5:*:windows:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:a:cisco:vpn_client:3.1:*:windows:*:*:*:*:*
3.5.1CPE matchmatch criteria
cpe:2.3:a:cisco:vpn_client:3.5.1:*:windows:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.1LOW

AV:L/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.50%
Probability of exploitation in next 30 days
EPSS Percentile
83.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-10190 · Nov 21, 2009
This CVE's current EPSS score of 0.0250 is in the 97th percentile among its peer group of 2,096 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

ciscovendor investigatingvia nvd_reference
View patch

References

packetstormsecurity.org / 0911-exploits/sybsec-adv17.txt
Exploit
secunia.com / advisories/37419
Vendor Advisory
tools.cisco.com / security/center/viewAlert.x
Vendor Advisory
securityfocus.com / bid/37077
Exploit
vupen.com / english/advisories/2009/3296
Vendor Advisory