Moneycontrol PRO
HomeNewsBusinessCERT-In cautions users about vulnerabilities in Cisco's VPN client

CERT-In cautions users about vulnerabilities in Cisco's VPN client

According to the agency, these vulnerabilities allow attackers to execute code in the targeted system or copy malicious files to key system directories.

November 02, 2022 / 09:55 IST

The Indian Computer Emergency Response Team (CERT-In) has cautioned citizens about vulnerabilities in AnyConnect, a commercial VPN client from Cisco that can allow hackers to gain access to a system.

According to Cisco's website, the VPN is widely used in IT services, including in India. Reviews from customers on the website show that AnyConnect's clients include Capgemini and others.

"It is reported that vulnerabilities in Cisco AnyConnect Secure Mobility Client for Windows are being exploited in the wild by threat actors," read the CERT-In advisory published on October 28.

According to the agency, these vulnerabilities allow attackers to execute code in the targeted system or copy malicious files to key system directories.

Dual vulnerability

Two vulnerabilities exist in Cisco AnyConnect. The CERT-In termed the first vulnerability as DLL Hijacking Vulnerability.

The vulnerability exists in AnyConnect's interprocess communication channel in this case. An interprocess communication channel is a mechanism that allows processes to communicate with one another and synchronise their actions.

"An attacker with valid access credentials on the system could exploit this vulnerability by sending a specially crafted interprocess message to the AnyConnect process," the advisory read.

An attacker can then execute arbitrary code on the system.

The second vulnerability is called Uncontrolled Search Path Vulnerability.

"This vulnerability exists in the installer component of Anyconnect for Windows due to an error while handling directory paths," the advisory read.

Similar to the first vulnerability, this vulnerability can be exploited by creating malicious files and copying them to the system directory.

"It is to be noted that these vulnerabilities are being exploited in the wild. An attacker could exploit these vulnerabilities in conjunction with other Windows privilege escalation flaws to conduct further attacks on the target system," the CERT-In added.

To mitigate these vulnerabilities, the agency urged users to apply the updates available on Cisco's website.

Earlier in June, Malaysia-based DragonForceIO targeted two Indian corporate VPNs and websites of Mumbai University and Thane city police. This was in response to comments against Prophet Mohammad.

Cybernetyx VPN and Logixal VPN were allegedly compromised by hackers. They also shared login credentials with designated IP addresses associated with the two corporate VPNs. In addition, they provided screenshots to corroborate their claims.

Later Logixal, which provides e-banking solutions, clarified to Moneycontrol that customer data was not affected due to the breach and that they were conducting further investigation.

Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
first published: Nov 2, 2022 09:55 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347