CVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service…
Does this matter?
Lower severity and a low EPSS score (2.50%). Track it; it rarely justifies an emergency change on its own.
Description
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.50% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- cisco/vpn client
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/0911-exploits/sybsec-adv17.txtExploit
- http://secunia.com/advisories/37419Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=19445Vendor Advisory
- http://www.securityfocus.com/bid/37077Exploit
- http://www.vupen.com/english/advisories/2009/3296Vendor Advisory
- http://packetstormsecurity.org/0911-exploits/sybsec-adv17.txtExploit
- http://secunia.com/advisories/37419Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=19445Vendor Advisory
- http://www.securityfocus.com/bid/37077Exploit
- http://www.vupen.com/english/advisories/2009/3296Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.