Security restrictions bypass in Cisco AnyConnect Secure Mobility Client - CVE-2017-12268
Published: October 5, 2017 / Updated: October 9, 2017
Vulnerability identifier: #VU8710
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-12268
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco AnyConnect Secure Mobility Client
Cisco AnyConnect Secure Mobility Client
Detailed vulnerability description
The vulnerability allows a local attacker to enable multiple network adapters.
The weakness exists in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client due to insufficient NAM policy enforcement. A local attacker can bypass security restrictions, enable multiple active network adapters and cause traffic to be sent via an unauthorized network interface.
The weakness exists in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client due to insufficient NAM policy enforcement. A local attacker can bypass security restrictions, enable multiple active network adapters and cause traffic to be sent via an unauthorized network interface.
How to mitigate CVE-2017-12268
Install update from vendor's website.