7.8
CVE-2017-3813
- EPSS 5.22%
- Veröffentlicht 09.02.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient implementation of the access controls. An attacker could exploit this vulnerability by opening the Internet Explorer browser. An exploit could allow the attacker to use Internet Explorer with the privileges of the SYSTEM user. This may allow the attacker to execute privileged commands on the targeted system. This vulnerability affects versions prior to released versions 4.4.00243 and later and 4.3.05017 and later. Cisco Bug IDs: CSCvc43976.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Anyconnect Secure Mobility Client Version4.0.00048
Cisco ≫ Anyconnect Secure Mobility Client Version4.0.00051
Cisco ≫ Anyconnect Secure Mobility Client Version4.0.00052
Cisco ≫ Anyconnect Secure Mobility Client Version4.0.00057
Cisco ≫ Anyconnect Secure Mobility Client Version4.0.00061
Cisco ≫ Anyconnect Secure Mobility Client Version4.1.00028
Cisco ≫ Anyconnect Secure Mobility Client Version4.1.02011
Cisco ≫ Anyconnect Secure Mobility Client Version4.1.04011
Cisco ≫ Anyconnect Secure Mobility Client Version4.1.06013
Cisco ≫ Anyconnect Secure Mobility Client Version4.1.06020
Cisco ≫ Anyconnect Secure Mobility Client Version4.1.08005
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.00096
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.01022
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.01035
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.02075
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.03013
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.04018
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.04039
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.05015
Cisco ≫ Anyconnect Secure Mobility Client Version4.2.06014
Cisco ≫ Anyconnect Secure Mobility Client Version4.3.00748
Cisco ≫ Anyconnect Secure Mobility Client Version4.3.01095
Cisco ≫ Anyconnect Secure Mobility Client Version4.3.02039
Cisco ≫ Anyconnect Secure Mobility Client Version4.3.03086
Cisco ≫ Anyconnect Secure Mobility Client Version4.3.04027
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 5.22% | 0.889 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.