CVE-2013-1130: Medium severity cisco anyconnect secure vulnerability
Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a crafted library file, aka Bug ID CSCue33619.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1130?
CVE-2013-1130 is classified as a high-severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2013-1130?
To mitigate CVE-2013-1130, ensure that the permissions on the library directory used by Cisco AnyConnect are appropriately restricted.
Who is affected by CVE-2013-1130?
CVE-2013-1130 affects users of Cisco AnyConnect Secure Mobility Client on Mac OS X with misconfigured library directory permissions.
What types of attacks can exploit CVE-2013-1130?
CVE-2013-1130 can be exploited by local users to escalate their privileges through crafted library files.
Is there a patch available for CVE-2013-1130?
Yes, Cisco has released updates for the AnyConnect Secure Mobility Client to address the vulnerabilities associated with CVE-2013-1130.