CVE-2018-0100
Summary
| CVE | CVE-2018-0100 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-18 06:29:00 UTC |
| Updated | 2019-10-09 23:31:00 UTC |
| Description | A vulnerability in the Profile Editor of the Cisco AnyConnect Secure Mobility Client could allow an unauthenticated, local attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of the XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by injecting a crafted XML file with malicious entries, which could allow the attacker to read and write files. Cisco Bug IDs: CSCvg19341. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Anyconnect Secure Mobility Client | All | All | All | All |
| Application | Cisco | Anyconnect Secure Mobility Client | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco AnyConnect Secure Mobility Client Profile Editor XML External Entity Processing Flaw Lets Remote Users Read and Write Information on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco AnyConnect Profile Editor XML External Entity Injection Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| Cisco AnyConnect Profile Editor CVE-2018-0100 Local XML External Entity Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.