CVE-2015-0663
mediumCVSS v3 Base Score
6.6
AV:L/AC:L/Au:N/C:N/I:C/A:C
EPSS Score
0.1%
Exploitation probability in 30 days
Top 76% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
None
Integrity
C
Availability
C
Vulnerability Report
Generated by CyberWatcher
Description
Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.
CWE
CWE-264Affected Products
cisco anyconnect secure mobility client