MEDIUM · 5.0

CVE-2014-3314

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka B...

Vulnerability Description

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 and CSCuo24940.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoAnyconnect Secure Mobility ClientAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3314?

CVE-2014-3314 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka B...

How severe is CVE-2014-3314?

CVE-2014-3314 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3314?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Anyconnect Secure Mobility Client.