Vulnerability CVE-2015-0761


Published: 2015-06-04

Description:
Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions, which allows local users to obtain root privileges via crafted vpnagent options, aka Bug ID CSCus86790.

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> Anyconnect secure mobility client 

 References:
http://tools.cisco.com/security/center/viewAlert.x?alertId=39158
http://www.securityfocus.com/bid/74954
http://www.securitytracker.com/id/1032472

Copyright 2024, cxsecurity.com

 

Back to Top