5
CVSSv2

CVE-2014-3314

Published: 14/01/2015 Updated: 11/05/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote malicious users to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 and CSCuo24940.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco anyconnect secure mobility client

Vendor Advisories

A vulnerability in Cisco AnyConnect for Android and Mac OS X could allow an unauthenticated, remote attacker to force the rendering of an authentication form in the client The vulnerability is due to insufficient validation of the type of host to which AnyConnect establishes a connection An attacker could exploit this issue by convincing a user ...