Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-945c-gxr5-cr85

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.

The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.

EPSS

Процентиль: 31%
0.00119
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 13 лет назад

The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.

EPSS

Процентиль: 31%
0.00119
Низкий

Дефекты

CWE-200