Cisco AnyConnect Secure Mobility Client < 3.1.8009.0 / 4.0.x < 4.0.2052.0 / 4.1.x < 4.1.28.0 Multiple Vulnerabilities

medium Nessus Plugin ID 85266

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The Cisco AnyConnect Secure Mobility Client installed on the remote host is a version prior to 3.1.8009.0, or is version 4.0.x prior to 4.0.2052.0, or version 4.1.x prior to 4.1.28.0. It is, therefore, affected by the following vulnerabilities :

- A flaw exists due to not sanitizing the input of IPC commands. A local attacker, using a specially crafted IPC command, can exploit this to write to arbitrary user space memory and execute code with escalated privileges.
(CVE-2015-0664)

- A path traversal flaw exists due to the Hostscan module not properly sanitizing user input in certain IPC commands. A local, authenticated attacker, using a specially crafted IPC command, can exploit this to traverse outside restricted paths and write or overwrite arbitrary files. (CVE-2015-0665)

Solution

Upgrade to Cisco AnyConnect Secure Mobility Client version 3.1.8009.0 / 4.0.2052.0 / 4.1.28.0 or later

See Also

https://tools.cisco.com/security/center/viewAlert.x?alertId=37861

https://tools.cisco.com/security/center/viewAlert.x?alertId=37862

Plugin Details

Severity: Medium

ID: 85266

File Name: cisco_anyconnect_CSCus79173_CSCus79195.nasl

Version: 1.4

Type: local

Agent: windows

Family: Windows

Published: 8/7/2015

Updated: 7/6/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Information

CPE: cpe:/a:cisco:anyconnect_secure_mobility_client

Required KB Items: SMB/Registry/Enumerated, installed_sw/Cisco AnyConnect Secure Mobility Client

Exploit Ease: No known exploits are available

Patch Publication Date: 5/8/2015

Vulnerability Publication Date: 3/14/2015

Reference Information

CVE: CVE-2015-0664, CVE-2015-0665

BID: 73120

CISCO-BUG-ID: CSCus79173, CSCus79195