SB2017100511 - Security restrictions bypass in Cisco AnyConnect Secure Mobility Client
Published: October 5, 2017 Updated: October 9, 2017
Security Bulletin ID
SB2017100511
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2017-12268)
The vulnerability allows a local attacker to enable multiple network adapters.The weakness exists in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client due to insufficient NAM policy enforcement. A local attacker can bypass security restrictions, enable multiple active network adapters and cause traffic to be sent via an unauthorized network interface.
Remediation
Install update from vendor's website.