Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8f4f-mpwv-cr26

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit this vulnerability.

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit this vulnerability.

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.5
nvd
около 5 лет назад

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit this vulnerability.

CVSS3: 5.5
fstec
около 5 лет назад

Уязвимость компонента обновления средства криптографической защиты Cisco AnyConnect Secure Mobility Client, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-269