← Back to browse · API

CVE-2020-3433

Severity
HIGH
CVSS
7.8
EPSS
0.10049
Risk score
59.72
CISA KEV
Yes
PoC
No
Published
2022-10-24
Modified
2022-10-24
First seen
2026-08-07
Aliases
EUVD-2020-24704, GHSA-V63M-WV25-VHMP
Products
Cisco:AnyConnect Secure, Cisco:Cisco AnyConnect Secure Mobility Client n/a
Sources
euvd EUVD-2020-24704
cisa.gov CVE-2020-3433

Description

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

References