Vulnerability Description
The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Anyconnect Secure Mobility Client | <= 4.0\(.00051\) |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=37862Vendor Advisory
- http://www.securitytracker.com/id/1031931
- http://tools.cisco.com/security/center/viewAlert.x?alertId=37862Vendor Advisory
- http://www.securitytracker.com/id/1031931
FAQ
What is CVE-2015-0665?
CVE-2015-0665 is a vulnerability with a CVSS score of 6.6 (MEDIUM). The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.
How severe is CVE-2015-0665?
CVE-2015-0665 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0665?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Anyconnect Secure Mobility Client.