Vulnslist

find the latest Cisco vulnerabilities

Cisco AnyConnect Secure Mobility Client Arbitrary File Move Vulnerability

cisco-sa-20151008-asmc · Medium · Published · Updated

A vulnerability in interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to move arbitrary files with elevated privileges. The vulnerability is due to missing source path validation in certain IPC commands. An attacker could exploit this vulnerability by sending crafted IPC messages. An exploit could allow the attacker to move arbitrary files with elevated privileges, which could affect the integrity of the system and cause a denial of service condition. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151008-asmc

Workarounds

Workarounds are not available.

CVEsCVE-2015-6322
Cisco Bug IDsCSCuv48563
CVSS ScoreBase 6.2
Base 6.2 AV:L/AC:L/Au:S/C:N/I:C/A:C/E:F/RL:U/RC:C
Product Names From Source
Cisco AnyConnect Secure Mobility Client, Cisco Secure Client

Related Products

Product CVE Evidence
Cisco Secure Client CVE-2015-6322 Cisco OpenVuln
Cisco AnyConnect Secure Mobility Client CVE-2015-6322 Cisco OpenVuln