CVE Vulnerabilities

CVE-2016-6369

Published: Aug 25, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

Affected Software

NameVendorStart VersionEnd Version
Anyconnect_secure_mobility_clientCisco2.0.0343 (including)2.0.0343 (including)
Anyconnect_secure_mobility_clientCisco2.1.0148 (including)2.1.0148 (including)
Anyconnect_secure_mobility_clientCisco2.2.0133 (including)2.2.0133 (including)
Anyconnect_secure_mobility_clientCisco2.2.0136 (including)2.2.0136 (including)
Anyconnect_secure_mobility_clientCisco2.2.0140 (including)2.2.0140 (including)
Anyconnect_secure_mobility_clientCisco2.3.0185 (including)2.3.0185 (including)
Anyconnect_secure_mobility_clientCisco2.3.0254 (including)2.3.0254 (including)
Anyconnect_secure_mobility_clientCisco2.3.1003 (including)2.3.1003 (including)
Anyconnect_secure_mobility_clientCisco2.3.2016 (including)2.3.2016 (including)
Anyconnect_secure_mobility_clientCisco2.4.0202 (including)2.4.0202 (including)
Anyconnect_secure_mobility_clientCisco2.4.1012 (including)2.4.1012 (including)
Anyconnect_secure_mobility_clientCisco2.5.0217 (including)2.5.0217 (including)
Anyconnect_secure_mobility_clientCisco2.5.2006 (including)2.5.2006 (including)
Anyconnect_secure_mobility_clientCisco2.5.2010 (including)2.5.2010 (including)
Anyconnect_secure_mobility_clientCisco2.5.2011 (including)2.5.2011 (including)
Anyconnect_secure_mobility_clientCisco2.5.2014 (including)2.5.2014 (including)
Anyconnect_secure_mobility_clientCisco2.5.2017 (including)2.5.2017 (including)
Anyconnect_secure_mobility_clientCisco2.5.2018 (including)2.5.2018 (including)
Anyconnect_secure_mobility_clientCisco2.5.2019 (including)2.5.2019 (including)
Anyconnect_secure_mobility_clientCisco2.5.3041 (including)2.5.3041 (including)
Anyconnect_secure_mobility_clientCisco2.5.3046 (including)2.5.3046 (including)
Anyconnect_secure_mobility_clientCisco2.5.3051 (including)2.5.3051 (including)
Anyconnect_secure_mobility_clientCisco2.5.3054 (including)2.5.3054 (including)
Anyconnect_secure_mobility_clientCisco2.5.3055 (including)2.5.3055 (including)
Anyconnect_secure_mobility_clientCisco2.5_base (including)2.5_base (including)
Anyconnect_secure_mobility_clientCisco3.0.0 (including)3.0.0 (including)
Anyconnect_secure_mobility_clientCisco3.0.0629 (including)3.0.0629 (including)
Anyconnect_secure_mobility_clientCisco3.0.1047 (including)3.0.1047 (including)
Anyconnect_secure_mobility_clientCisco3.0.2052 (including)3.0.2052 (including)
Anyconnect_secure_mobility_clientCisco3.0.3050 (including)3.0.3050 (including)
Anyconnect_secure_mobility_clientCisco3.0.3054 (including)3.0.3054 (including)
Anyconnect_secure_mobility_clientCisco3.0.4235 (including)3.0.4235 (including)
Anyconnect_secure_mobility_clientCisco3.0.5075 (including)3.0.5075 (including)
Anyconnect_secure_mobility_clientCisco3.0.5080 (including)3.0.5080 (including)
Anyconnect_secure_mobility_clientCisco3.0.09231 (including)3.0.09231 (including)
Anyconnect_secure_mobility_clientCisco3.0.09266 (including)3.0.09266 (including)
Anyconnect_secure_mobility_clientCisco3.0.09353 (including)3.0.09353 (including)
Anyconnect_secure_mobility_clientCisco3.1(60) (including)3.1(60) (including)
Anyconnect_secure_mobility_clientCisco3.1.0 (including)3.1.0 (including)
Anyconnect_secure_mobility_clientCisco3.1.02043 (including)3.1.02043 (including)
Anyconnect_secure_mobility_clientCisco3.1.05182 (including)3.1.05182 (including)
Anyconnect_secure_mobility_clientCisco3.1.05187 (including)3.1.05187 (including)
Anyconnect_secure_mobility_clientCisco3.1.06073 (including)3.1.06073 (including)
Anyconnect_secure_mobility_clientCisco3.1.07021 (including)3.1.07021 (including)
Anyconnect_secure_mobility_clientCisco4.0(48) (including)4.0(48) (including)
Anyconnect_secure_mobility_clientCisco4.0(64) (including)4.0(64) (including)
Anyconnect_secure_mobility_clientCisco4.0(2049) (including)4.0(2049) (including)
Anyconnect_secure_mobility_clientCisco4.0.0 (including)4.0.0 (including)
Anyconnect_secure_mobility_clientCisco4.0.00048 (including)4.0.00048 (including)
Anyconnect_secure_mobility_clientCisco4.0.00051 (including)4.0.00051 (including)
Anyconnect_secure_mobility_clientCisco4.1(8) (including)4.1(8) (including)
Anyconnect_secure_mobility_clientCisco4.1.0 (including)4.1.0 (including)
Anyconnect_secure_mobility_clientCisco4.2.0 (including)4.2.0 (including)
Anyconnect_secure_mobility_clientCisco4.2.04039 (including)4.2.04039 (including)
Anyconnect_secure_mobility_clientCisco4.3.0 (including)4.3.0 (including)
Anyconnect_secure_mobility_clientCisco4.3.00748 (including)4.3.00748 (including)
Anyconnect_secure_mobility_clientCisco4.3.01095 (including)4.3.01095 (including)

References