meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 5th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 November 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cisco AnyConnect Vuln; Chrome Root CA Policy; Android Security Bulletin

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 5th, 2020 edition of the Sansonet Stormsanders Stormcast.

0:07.6

My name is Johannes Ulrich.

0:09.2

And today I'm recording from Jacksonville, Florida.

0:14.1

Cisco today released a patch for the AnyConnect secure mobility client.

0:19.0

And I think this is a tricky vulnerability.

0:22.0

Really come up with a correct sort of severity rating and how quickly you should patch this.

0:28.9

The CVSS score is 7.3.

0:32.0

So again, you're not super critical.

0:35.2

And Cisco rates it as high.

0:37.8

Now, let me walk you through some of the pros and cons,

0:41.0

why this may or may not be a real important or critical vulnerability for you.

0:47.5

First of all, well, it is arbitrary code execution.

0:51.2

So that definitely puts it up there.

0:58.9

And it's due to the IPC listener not requiring any authentication. However, to exploit this vulnerability, the attacker has to have credentials

1:06.1

on the system for which the attacker would like to exploit the vulnerability on.

1:12.6

So that's a big if here.

1:15.6

And the victim needs to have an active mobility client connection going at the time of the attack.

1:23.6

And then there's this interesting requirement that you're only vulnerable if you have the

1:28.1

auto update feature enabled. So actually, this abling auto update is provided here as a mitigation

1:36.4

for the vulnerability. So in some ways, you can say, hey, if the user has auto update enabled,

1:43.2

then they'll get the new version of

1:45.7

the client, so the vulnerability will be taken care of.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.