CVE-2015-0761Cisco Anyconnect Secure Mobility Client vulnerability

CWE-2644 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 68.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateMay 17

Description

Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions, which allows local users to obtain root privileges via crafted vpnagent options, aka Bug ID CSCus86790.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-pxqm-p9p2-q93c: Cisco AnyConnect Secure Mobility Client before 32022-05-17
CVEList
CVE-2015-0761: Cisco AnyConnect Secure Mobility Client before 32015-06-04

📋Vendor Advisories

1
Cisco
Cisco AnyConnect Secure Mobility Client Privilege Escalation Vulnerability2015-06-02
CVE-2015-0761 — Cisco vulnerability | cvebase