Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-2041 | First vendor Publication | 2011-06-02 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2041 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
72716 | Cisco AnyConnect Secure Mobility Client Start Before Logon Unspecified Local ... |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Cisco AnyConnect ActiveX clsid access RuleID : 19909 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | Cisco AnyConnect ActiveX function call access RuleID : 19651 - Revision : 7 - Type : BROWSER-PLUGINS |
2014-01-10 | Cisco AnyConnect ActiveX clsid access RuleID : 19650 - Revision : 10 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-12-16 | Name : The remote host has software installed that is affected by multiple vulnerabi... File : macosx_cisco_anyconnect_3_0_629.nasl - Type : ACT_GATHER_INFO |
2011-06-03 | Name : The VPN client installed on the remote Windows host has multiple vulnerabilit... File : cisco_anyconnect_vpn_2_3_254.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:04 |
|
2024-11-28 12:25:47 |
|
2021-01-21 01:06:40 |
|
2020-05-24 01:07:49 |
|
2020-05-23 01:44:32 |
|
2020-05-23 00:28:34 |
|
2018-02-16 12:02:19 |
|
2016-06-28 18:40:15 |
|
2016-04-26 20:46:42 |
|
2014-02-17 11:02:37 |
|
2013-05-10 23:01:03 |
|