First published: Thu Apr 11 2013(Updated: )
The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco AnyConnect Secure Mobility Client | ||
Cisco AnyConnect Secure Mobility Client | =2.0 | |
Cisco AnyConnect Secure Mobility Client | =2.1 | |
Cisco AnyConnect Secure Mobility Client | =2.2 | |
Cisco AnyConnect Secure Mobility Client | =2.2.128 | |
Cisco AnyConnect Secure Mobility Client | =2.2.133 | |
Cisco AnyConnect Secure Mobility Client | =2.2.136 | |
Cisco AnyConnect Secure Mobility Client | =2.2.140 | |
Cisco AnyConnect Secure Mobility Client | =2.3 | |
Cisco AnyConnect Secure Mobility Client | =2.3.185 | |
Cisco AnyConnect Secure Mobility Client | =2.3.254 | |
Cisco AnyConnect Secure Mobility Client | =2.3.2016 | |
Cisco AnyConnect Secure Mobility Client | =2.4 | |
cisco AnyConnect Secure Mobility Client symbian os | =2.4 | |
Cisco AnyConnect Secure Mobility Client | =2.4.0202 | |
Cisco AnyConnect Secure Mobility Client | =2.4.1012 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.4.4004 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.4.4014 | |
cisco AnyConnect Secure Mobility Client symbian os | =2.4.5004 | |
cisco AnyConnect Secure Mobility Client android | =2.4.7030 | |
cisco AnyConnect Secure Mobility Client android | =2.4.7073 | |
Cisco AnyConnect Secure Mobility Client | =2.5 | |
Cisco AnyConnect Secure Mobility Client | =2.5.0217 | |
Cisco AnyConnect Secure Mobility Client | =2.5.1025 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2001 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2006 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2010 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2011 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2014 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2017 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2018 | |
Cisco AnyConnect Secure Mobility Client | =2.5.2019 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3041 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3046 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3051 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3054 | |
Cisco AnyConnect Secure Mobility Client | =2.5.3055 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.5.5112 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5116 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5118 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5125 | |
cisco AnyConnect Secure Mobility Client iphone os | =2.5.5130 | |
cisco AnyConnect Secure Mobility Client android | =2.5.5131 | |
Cisco AnyConnect Secure Mobility Client | =2.5.6005 | |
Cisco AnyConnect Secure Mobility Client | =3.0 | |
Cisco AnyConnect Secure Mobility Client | =3.0 | |
Cisco AnyConnect Secure Mobility Client | =3.0.0629 | |
Cisco AnyConnect Secure Mobility Client | =3.0.1047 | |
Cisco AnyConnect Secure Mobility Client | =3.0.2052 | |
Cisco AnyConnect Secure Mobility Client | =3.0.3050 | |
Cisco AnyConnect Secure Mobility Client | =3.0.3054 | |
Cisco AnyConnect Secure Mobility Client | =3.0.4235 | |
Cisco AnyConnect Secure Mobility Client | =3.0.5075 | |
Cisco AnyConnect Secure Mobility Client | =3.0.5080 | |
Cisco AnyConnect Secure Mobility Client | =3.0.07059 | |
Cisco AnyConnect Secure Mobility Client | =3.0.08057 | |
Cisco AnyConnect Secure Mobility Client | =3.0.08057 | |
Cisco AnyConnect Secure Mobility Client | =3.0.08066 | |
Cisco AnyConnect Secure Mobility Client | =3.1.0 | |
Cisco AnyConnect Secure Mobility Client | =3.1.00495 | |
Cisco AnyConnect Secure Mobility Client | =3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1172 has a CVSS base score of 7.8, indicating it is a high severity vulnerability.
To fix CVE-2013-1172, you should upgrade to the latest version of the Cisco AnyConnect Secure Mobility Client that addresses this vulnerability.
CVE-2013-1172 affects multiple versions, including 2.0 to 3.2.0 of Cisco AnyConnect Secure Mobility Client.
CVE-2013-1172 requires local access for exploitation, meaning an attacker must have physical access to the machine.
The impact of CVE-2013-1172 allows local users to gain elevated privileges on affected systems.