PT-2019-2290 · Cisco · Cisco Anyconnect Secure Mobility Client

Robert Scott

·

Publicado

2019-05-15

·

Atualizado

2019-10-09

·

CVE-2019-1853

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client for Linux (affected versions not specified)
Description A vulnerability in the HostScan component could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The issue exists due to improper bounds checks, allowing an attacker to exploit it by crafting HTTP traffic for the affected component to download and process. A successful exploit could allow the attacker to read sensitive information on the affected system. The vulnerability is related to a buffer overflow in memory, which can be exploited using specially crafted HTTP traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02061
CVE-2019-1853

Produtos afetados

Cisco Anyconnect Secure Mobility Client