CVE-2017-6788
Summary
| CVE | CVE-2017-6788 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-17 20:29:00 UTC |
| Updated | 2017-08-24 16:08:00 UTC |
| Description | The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the WebLaunch function of the affected software. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request. Cisco Bug IDs: CSCvf12055. Known Affected Releases: 98.89(40). |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Anyconnect Secure Mobility Client | 4.4(4027) | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 4.4\(4027\) | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 4.5(58) | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 4.5\(58\) | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 4.4\(4027\) | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | 4.5\(58\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco AnyConnect WebLaunch Cross-Site Scripting Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| Cisco AnyConnect Secure Mobility Client Input Validation Flaw in WebLaunch Function Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco AnyConnect Secure Mobility Client Software CVE-2017-6788 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.