cbcvebase.
CVE-2015-7600
published 2015-10-06

CVE-2015-7600: Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program…

PriorityP433high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.54%
41.5th percentile
Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.

Affected

20 ranges
VendorProductVersion rangeFixed in
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client
ciscovpn_client

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.