CVE-2018-0334Improper Certificate Validation in Cisco Anyconnect Secure Mobility Client

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 77.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 13

Description

A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote attacker to bypass the TLS certificate check when downloading certain configuration files. The vulnerability is due to improper use of Simple Certificate Enrollment Protocol and improper server certificate validation. An attacker could exploit this vulnerability by pr

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-4p6c-fxcr-rhm3: A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for2022-05-13
CVEList
CVE-2018-0334: A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for2018-06-07

📋Vendor Advisories

1
Cisco
Cisco AnyConnect Secure Mobility Client Certificate Bypass Vulnerability2018-06-06

💬Community

1
Bugzilla
CVE-2018-6056 chromium-browser: incorrect derived class instantiation in v82018-02-14
CVE-2018-0334 — Improper Certificate Validation | cvebase