CVE Database
/

CVE-2017-12268

Back to search

CVE-2017-12268

Published: Oct 5, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insufficient NAM policy enforcement. An attacker could exploit this vulnerability by manipulating network interfaces of the device to allow multiple active network interfaces. A successful exploit could allow the attacker to send traffic over a non-authorized network interface. Cisco Bug IDs: CSCvf66539.

VendorProductVersions

n/a

Cisco AnyConnect Network Access Manager

affected
Cisco AnyConnect Network Access Manager

Weaknesses (CWE)

References

1039507
vdb-entry
x_refsource_SECTRACK
101157
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now