#VU8710 Security restrictions bypass in Cisco AnyConnect Secure Mobility Client - CVE-2017-12268
Published: October 5, 2017 / Updated: October 9, 2017
Vulnerability identifier: #VU8710
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-12268
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco AnyConnect Secure Mobility Client
Cisco AnyConnect Secure Mobility Client
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a local attacker to enable multiple network adapters.
The weakness exists in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client due to insufficient NAM policy enforcement. A local attacker can bypass security restrictions, enable multiple active network adapters and cause traffic to be sent via an unauthorized network interface.
The weakness exists in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client due to insufficient NAM policy enforcement. A local attacker can bypass security restrictions, enable multiple active network adapters and cause traffic to be sent via an unauthorized network interface.
Remediation
Install update from vendor's website.