CVE-2015-6322

medium
Published 2015-10-12 · Modified 2026-05-06
CVSS v3
VIR risk
6.6

Description

The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move arbitrary files by leveraging the lack of source-path validation, aka Bug ID CSCuv48563.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
cisco ciscoanyconnect_secure_mobility_client2.0.0343
cisco ciscoanyconnect_secure_mobility_client2.1.0148
cisco ciscoanyconnect_secure_mobility_client2.2.0133
cisco ciscoanyconnect_secure_mobility_client2.2.0136
cisco ciscoanyconnect_secure_mobility_client2.2.0140
cisco ciscoanyconnect_secure_mobility_client2.3.0185
cisco ciscoanyconnect_secure_mobility_client2.3.0254
cisco ciscoanyconnect_secure_mobility_client2.3.1003
cisco ciscoanyconnect_secure_mobility_client2.3.2016
cisco ciscoanyconnect_secure_mobility_client2.4.0202
cisco ciscoanyconnect_secure_mobility_client2.4.1012
cisco ciscoanyconnect_secure_mobility_client2.5.0217
cisco ciscoanyconnect_secure_mobility_client2.5.2006
cisco ciscoanyconnect_secure_mobility_client2.5.2010
cisco ciscoanyconnect_secure_mobility_client2.5.2011
cisco ciscoanyconnect_secure_mobility_client2.5.2014
cisco ciscoanyconnect_secure_mobility_client2.5.2017
cisco ciscoanyconnect_secure_mobility_client2.5.2018
cisco ciscoanyconnect_secure_mobility_client2.5.2019
cisco ciscoanyconnect_secure_mobility_client2.5.3041
cisco ciscoanyconnect_secure_mobility_client2.5.3046
cisco ciscoanyconnect_secure_mobility_client2.5.3051
cisco ciscoanyconnect_secure_mobility_client2.5.3054
cisco ciscoanyconnect_secure_mobility_client2.5.3055
cisco ciscoanyconnect_secure_mobility_client2.5_base
cisco ciscoanyconnect_secure_mobility_client3.0.0
cisco ciscoanyconnect_secure_mobility_client3.0.0629
cisco ciscoanyconnect_secure_mobility_client3.0.1047
cisco ciscoanyconnect_secure_mobility_client3.0.2052
cisco ciscoanyconnect_secure_mobility_client3.0.3050
cisco ciscoanyconnect_secure_mobility_client3.0.3054
cisco ciscoanyconnect_secure_mobility_client3.0.4235
cisco ciscoanyconnect_secure_mobility_client3.0.5075
cisco ciscoanyconnect_secure_mobility_client3.0.5080
cisco ciscoanyconnect_secure_mobility_client3.0.09231
cisco ciscoanyconnect_secure_mobility_client3.0.09266
cisco ciscoanyconnect_secure_mobility_client3.0.09353
cisco ciscoanyconnect_secure_mobility_client3.1\(60\)
cisco ciscoanyconnect_secure_mobility_client3.1.0
cisco ciscoanyconnect_secure_mobility_client3.1.02043
cisco ciscoanyconnect_secure_mobility_client3.1.05182
cisco ciscoanyconnect_secure_mobility_client3.1.05187
cisco ciscoanyconnect_secure_mobility_client3.1.06073
cisco ciscoanyconnect_secure_mobility_client3.1.07021
cisco ciscoanyconnect_secure_mobility_client4.0\(48\)
cisco ciscoanyconnect_secure_mobility_client4.0\(64\)
cisco ciscoanyconnect_secure_mobility_client4.0\(2049\)
cisco ciscoanyconnect_secure_mobility_client4.0.0
cisco ciscoanyconnect_secure_mobility_client4.0.00048
cisco ciscoanyconnect_secure_mobility_client4.0.00051
cisco ciscoanyconnect_secure_mobility_client4.1\(8\)
cisco ciscoanyconnect_secure_mobility_client4.1.0

References

CWEs

CWE-264

💬 Discuss CVE-2015-6322 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.