Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j35p-59jh-58v4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

EPSS

Процентиль: 29%
0.00103
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 13 лет назад

Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

EPSS

Процентиль: 29%
0.00103
Низкий

Дефекты

CWE-287