PT-2015-7169 · Cisco · Cisco Anyconnect Secure Mobility Client

Yorick Koster

·

Publicado

2015-09-25

·

Atualizado

2018-10-09

·

CVE-2015-6306

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client version 4.1(8)
Description The issue allows local users to obtain root privileges via a crafted installation file because the software does not verify pathnames before installation actions.
Recommendations For Cisco AnyConnect Secure Mobility Client version 4.1(8), update to a version that includes the fix for Bug ID CSCuv11947 to prevent local users from obtaining root privileges.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6306

Produtos afetados

Cisco Anyconnect Secure Mobility Client