CVE-2015-0665
medium
CVSS v3
—
CVSS v2
6.6
VIR risk
6.6
Description
The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/viewAlert.x?alertId=37862
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | anyconnect_secure_mobility_client | {"endIncluding":"4.0\\(.00051\\)"} | |
References
CWEs
CWE-22
Verify integrity in audit chain (admin only). AS-IS.