CVE-2015-0663Cisco Anyconnect Secure Mobility Client vulnerability

CWE-2644 documents4 sources
Severity
6.6MEDIUMNVD
EPSS
0.1%
top 75.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.

CVSS vector

AV:L/AC:L/C:N/I:C/A:CExploitability: 3.9 | Impact: 9.2

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w677-pf97-rqh8: Cisco AnyConnect Secure Mobility Client 42022-05-17
CVEList
CVE-2015-0663: Cisco AnyConnect Secure Mobility Client 42015-03-17

📋Vendor Advisories

1
Cisco
Cisco AnyConnect Secure Mobility Client Arbitrary File Write Vulnerability2015-03-14
CVE-2015-0663 — Cisco vulnerability | cvebase