Vulnerability Details CVE-2021-34788
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition in the signature verification process for shared library files that are loaded on an affected device. An attacker could exploit this vulnerability by sending a series of crafted interprocess communication (IPC) messages to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected device with root privileges. To exploit this vulnerability, the attacker must have a valid account on the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.2%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 6.9
Products affected by CVE-2021-34788
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:-
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.0
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.1
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.128
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.133
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.136
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.140
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.3
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.3.185
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.3.2016
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.3.254
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.0202
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.1012
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.4004
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.4014
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.5004
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.7030
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.4.7073
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.0217
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.1025
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2001
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2006
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2010
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2011
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2014
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2017
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2018
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.2019
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.3041
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.3046
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.3051
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.3054
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.3055
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.5112
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.5116
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.5118
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.5125
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.5130
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.5131
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.5.6005
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.0629
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.07059
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.08057
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.08066
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.1047
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.2052
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.3050
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.3054
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.4235
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.5075
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.0.5080
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.1(.02043)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.1(.07021)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.1(60)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.1.0
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.1.00495
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:3.2.0
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0(.00048)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0(.00051)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0(2049)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00052
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00057
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.0.00061
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.00028
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.02011
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.04011
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.06013
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.06020
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.08005
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.0
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.00096
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.01022
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.01035
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.02075
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.03013
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.04018
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.04039
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.05015
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.2.06014
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.3.0
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.3.00748
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.3.01095
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.3.02039
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.3.03086
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.3.04027
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.4(4027)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.4.00243
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(1044)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(2033)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(2036)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(3040)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(4029)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(5030)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(58)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.5(822)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.6(100)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.6(1098)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.6(200)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.6(2074)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.6(362)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.00175
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.00820
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.00826
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.01090
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.01098
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.02042
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.02045
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03036
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03043
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03052
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03537
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03538
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03645
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.8.03651
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9(3052)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9(5086)
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.00086
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.01095
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.02028
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.03047
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.03049
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.04043
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.04053
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.05042
-
cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.9.06037
-
-
cpe:2.3:o:linux:linux_kernel:-