CVE-2015-0664Improper Input Validation in Cisco Anyconnect Secure Mobility Client

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 77.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 17

Description

The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and consequently gain privileges, via crafted messages, aka Bug ID CSCus79195.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.1 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jf8j-hmx6-pcgf: The IPC channel in Cisco AnyConnect Secure Mobility Client 42022-05-17
CVEList
CVE-2015-0664: The IPC channel in Cisco AnyConnect Secure Mobility Client 42015-03-18

📋Vendor Advisories

1
Cisco
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability2015-03-14
CVE-2015-0664 — Improper Input Validation in Cisco | cvebase