CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:S/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
47.6%
The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | anyconnect_secure_mobility_client | - | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:-:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.0 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.0:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.1 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.1:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.2 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.2.128 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.128:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.2.133 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.133:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.2.136 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.136:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.2.140 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.140:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.3 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.3:*:*:*:*:*:*:* |
cisco | anyconnect_secure_mobility_client | 2.3.185 | cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.3.185:*:*:*:*:*:*:* |