Cisco Systems VPN Client for Windows Dangerous Dialog Instructions Weakness
BID:4611
Info
Cisco Systems VPN Client for Windows Dangerous Dialog Instructions Weakness
| Bugtraq ID: | 4611 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 17 2002 12:00AM |
| Updated: | Apr 17 2002 12:00AM |
| Credit: | Published by Kayne Ian <[email protected]>. |
| Vulnerable: |
Cisco VPN Client for Windows 3.5.1 Cisco VPN Client for Windows 3.1 |
| Not Vulnerable: | |
Discussion
Cisco Systems VPN Client for Windows Dangerous Dialog Instructions Weakness
The Cisco Systems VPN Client is available for Windows, Linux, Solaris and Mac OS X. A potential threat has been reported in the installation process of the VPN Client for Windows XP.
As part of the installation process. the user is advised to reduce Windows security settings related to the installation of unsigned drivers. The user is not advised to reset this setting when installation is complete, possibly impacting system security settings.
The Cisco Systems VPN Client is available for Windows, Linux, Solaris and Mac OS X. A potential threat has been reported in the installation process of the VPN Client for Windows XP.
As part of the installation process. the user is advised to reduce Windows security settings related to the installation of unsigned drivers. The user is not advised to reset this setting when installation is complete, possibly impacting system security settings.
Exploit / POC
Cisco Systems VPN Client for Windows Dangerous Dialog Instructions Weakness
No exploit is required.
No exploit is required.
Solution / Fix
Cisco Systems VPN Client for Windows Dangerous Dialog Instructions Weakness
Solution:
Reportedly Cisco plans to remove this advice in version 3.6 of the client software. A release date is not currently known.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly Cisco plans to remove this advice in version 3.6 of the client software. A release date is not currently known.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cisco Systems VPN Client for Windows Dangerous Dialog Instructions Weakness
References:
References:
- VPN Client (Cisco Systems)