CVE-2015-0665: Path Traversal
The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0665?
CVE-2015-0665 is classified as a high-severity vulnerability due to its potential for unauthorized file manipulation.
How do I fix CVE-2015-0665?
To mitigate CVE-2015-0665, users should upgrade to a later version of Cisco AnyConnect Secure Mobility Client that is not impacted by this vulnerability.
What is the impact of CVE-2015-0665?
The impact of CVE-2015-0665 allows local users to write to arbitrary files, which can compromise the integrity of the system.
Who is affected by CVE-2015-0665?
CVE-2015-0665 affects users of Cisco AnyConnect Secure Mobility Client version 4.0(.00051) and earlier.
What type of vulnerability is CVE-2015-0665?
CVE-2015-0665 is a local privilege escalation vulnerability within the Hostscan module of Cisco AnyConnect.