Vulnerability Description
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Anyconnect Secure Mobility Client | 4.1.\(8\) |
| Apple | Mac Os X | All versions |
| Linux | Linux Kernel | All versions |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/133685/Cisco-AnyConnect-DMG-Install-Script-ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2015/Sep/86Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=41135Vendor Advisory
- http://www.securityfocus.com/archive/1/536534/100/0/threaded
- http://www.securitytracker.com/id/1033656Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/38303/ExploitThird Party AdvisoryVDB Entry
- https://www.securify.nl/advisory/SFY20150701/cisco_anyconnect_elevation_%20of_prPatchThird Party Advisory
- http://packetstormsecurity.com/files/133685/Cisco-AnyConnect-DMG-Install-Script-ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2015/Sep/86Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=41135Vendor Advisory
- http://www.securityfocus.com/archive/1/536534/100/0/threaded
- http://www.securitytracker.com/id/1033656Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/38303/ExploitThird Party AdvisoryVDB Entry
- https://www.securify.nl/advisory/SFY20150701/cisco_anyconnect_elevation_%20of_prPatchThird Party Advisory
FAQ
What is CVE-2015-6306?
CVE-2015-6306 is a vulnerability with a CVSS score of 7.2 (HIGH). Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation fi...
How severe is CVE-2015-6306?
CVE-2015-6306 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6306?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Anyconnect Secure Mobility Client, Apple Mac Os X, Linux Linux Kernel.