Skip to main content

Cisco AnyConnect Secure Mobility Client Software Update Vulnerability

Last Update Date: 21 Jun 2012 10:47 Release Date: 21 Jun 2012 4701 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Cisco AnyConnect Secure Mobility Client. A remote user can cause arbitrary code to be executed on the target user's system.

  1. A remote user can create a specially crafted HTML that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user.
  2. An input validation flaw allows remote code execution.
  3. A remote user can cause the target user to download and install an older version of the client software.
  4. A remote user can trigger a flaw in the 64-bit Java applet to execute arbitrary code.

Impact

  • Remote Code Execution

System / Technologies affected

  • Versions 2.5.x, 3.0.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link