CVE-2017-6788: XSS
The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the WebLaunch function of the affected software. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request. Cisco Bug IDs: CSCvf12055. Known Affected Releases: 98.89(40).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6788?
CVE-2017-6788 has a medium severity rating allowing potential cross-site scripting attacks.
How do I fix CVE-2017-6788?
To fix CVE-2017-6788, update Cisco AnyConnect Secure Mobility Client to version 4.4(4028) or later, or 4.5(59) or later.
Which versions of Cisco AnyConnect are affected by CVE-2017-6788?
CVE-2017-6788 affects Cisco AnyConnect Secure Mobility Client versions 4.4(4027) and 4.5(58).
What type of attack can CVE-2017-6788 facilitate?
CVE-2017-6788 can facilitate a cross-site scripting (XSS) attack against users of the affected Cisco AnyConnect software.
Who can exploit CVE-2017-6788?
CVE-2017-6788 can be exploited by an unhauthenticated remote attacker.