Security restrictions bypass in Cisco AnyConnect Secure Mobility Client - CVE-2017-12268

 

Security restrictions bypass in Cisco AnyConnect Secure Mobility Client - CVE-2017-12268

Published: October 5, 2017 / Updated: October 9, 2017


Vulnerability identifier: #VU8710
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12268
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to enable multiple network adapters.

The weakness exists in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client due to insufficient NAM policy enforcement. A local attacker can bypass security restrictions, enable multiple active network adapters and cause traffic to be sent via an unauthorized network interface.

Affected software

Cisco AnyConnect Secure Mobility Client

How to mitigate CVE-2017-12268

Install update from vendor's website.


External References

Related Security Bulletins