CVE-2018-0334
published 2018-06-07CVE-2018-0334: A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac…
PriorityP426medium4.8CVSS 3.0
AVNACHPRNUINSUCLILAN
EPSS
0.98%
58.2th percentile
A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote attacker to bypass the TLS certificate check when downloading certain configuration files. The vulnerability is due to improper use of Simple Certificate Enrollment Protocol and improper server certificate validation. An attacker could exploit this vulnerability by preparing malicious profile and localization files for Cisco AnyConnect to use. A successful exploit could allow the attacker to remotely change the configuration profile, a certificate, or the localization data used by AnyConnect Secure Mobility Client. Cisco Bug IDs: CSCvh23141.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4p6c-fxcr-rhm3: A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for
ghsa_unreviewed·2022-05-13
CVE-2018-0334 [MEDIUM] CWE-295 GHSA-4p6c-fxcr-rhm3: A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for
A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote attacker to bypass the TLS certificate check when downloading certain configuration files. The vulnerability is due to improper use of Simple Certificate Enrollment Protocol and improper server certificate validation. An attacker could exploit this vulnerability by preparing malicious profile and localization files for Cisco AnyConnect to use. A successful exploit could allow the attacker to remotely change the configuration profile, a certificate, or the localization data used by AnyConnect Secure Mobility Client. Cisco Bug IDs: CSCvh23141.
Cisco
Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability
vendor_cisco·2018-06-06·CVSS 4.8
CVE-2018-0334 [MEDIUM] CWE-295 Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability
Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability
A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote
attacker to bypass the TLS certificate check when downloading certain configuration files.
The vulnerability is due to improper use of Simple Certificate Enrollment Protocol and improper server certificate validation. An attacker could
exploit this vulnerability by preparing malicious profile and localization files for Cisco AnyConnect to use. A successful exploit could allow the
attacker to remotely change the configuration profile, a certificate, or the localization data used by AnyConne
Cisco
Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0334 Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability
CVE-2018-0334: Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability
A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote attacker to bypass the TLS certificate check when downloading certain configuration files. The vulnerability is due to improper use of Simple Certificate Enrollment Protocol and improper server certificate validation. An attacker could exploit this vulnerability by preparing malicious profile and localization files for Cisco AnyConnect to use. A successful exploit could allow the attacker to remotely change the configuration profile, a certificate, or the localization data us
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/104430http://www.securitytracker.com/id/1041075https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-AnyConnect-cert-bypasshttp://www.securityfocus.com/bid/104430http://www.securitytracker.com/id/1041075https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-AnyConnect-cert-bypass
2018-06-07
Published