CVE-2015-0665Path Traversal in Cisco Anyconnect Secure Mobility Client

CWE-22Path Traversal4 documents4 sources
Severity
6.6MEDIUMNVD
EPSS
0.1%
top 77.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.

CVSS vector

AV:L/AC:L/C:N/I:C/A:CExploitability: 3.9 | Impact: 9.2

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-97h6-h2xq-qh36: The Hostscan module in Cisco AnyConnect Secure Mobility Client 42022-05-17
CVEList
CVE-2015-0665: The Hostscan module in Cisco AnyConnect Secure Mobility Client 42015-03-17

📋Vendor Advisories

1
Cisco
Cisco AnyConnect Secure Mobility Client Hostscan Path Traversal Vulnerability2015-03-14
CVE-2015-0665 — Path Traversal in Cisco | cvebase