CVE Vulnerabilities

CVE-2016-6369

Published: Aug 25, 2016 | Modified: Dec 12, 2016
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

Affected Software

Name Vendor Start Version End Version
Anyconnect_secure_mobility_client Cisco 2.0.0343 (including) 2.0.0343 (including)
Anyconnect_secure_mobility_client Cisco 2.1.0148 (including) 2.1.0148 (including)
Anyconnect_secure_mobility_client Cisco 2.2.0133 (including) 2.2.0133 (including)
Anyconnect_secure_mobility_client Cisco 2.2.0136 (including) 2.2.0136 (including)
Anyconnect_secure_mobility_client Cisco 2.2.0140 (including) 2.2.0140 (including)
Anyconnect_secure_mobility_client Cisco 2.3.0185 (including) 2.3.0185 (including)
Anyconnect_secure_mobility_client Cisco 2.3.0254 (including) 2.3.0254 (including)
Anyconnect_secure_mobility_client Cisco 2.3.1003 (including) 2.3.1003 (including)
Anyconnect_secure_mobility_client Cisco 2.3.2016 (including) 2.3.2016 (including)
Anyconnect_secure_mobility_client Cisco 2.4.0202 (including) 2.4.0202 (including)
Anyconnect_secure_mobility_client Cisco 2.4.1012 (including) 2.4.1012 (including)
Anyconnect_secure_mobility_client Cisco 2.5.0217 (including) 2.5.0217 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2006 (including) 2.5.2006 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2010 (including) 2.5.2010 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2011 (including) 2.5.2011 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2014 (including) 2.5.2014 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2017 (including) 2.5.2017 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2018 (including) 2.5.2018 (including)
Anyconnect_secure_mobility_client Cisco 2.5.2019 (including) 2.5.2019 (including)
Anyconnect_secure_mobility_client Cisco 2.5.3041 (including) 2.5.3041 (including)
Anyconnect_secure_mobility_client Cisco 2.5.3046 (including) 2.5.3046 (including)
Anyconnect_secure_mobility_client Cisco 2.5.3051 (including) 2.5.3051 (including)
Anyconnect_secure_mobility_client Cisco 2.5.3054 (including) 2.5.3054 (including)
Anyconnect_secure_mobility_client Cisco 2.5.3055 (including) 2.5.3055 (including)
Anyconnect_secure_mobility_client Cisco 2.5_base (including) 2.5_base (including)
Anyconnect_secure_mobility_client Cisco 3.0.0 (including) 3.0.0 (including)
Anyconnect_secure_mobility_client Cisco 3.0.0629 (including) 3.0.0629 (including)
Anyconnect_secure_mobility_client Cisco 3.0.1047 (including) 3.0.1047 (including)
Anyconnect_secure_mobility_client Cisco 3.0.2052 (including) 3.0.2052 (including)
Anyconnect_secure_mobility_client Cisco 3.0.3050 (including) 3.0.3050 (including)
Anyconnect_secure_mobility_client Cisco 3.0.3054 (including) 3.0.3054 (including)
Anyconnect_secure_mobility_client Cisco 3.0.4235 (including) 3.0.4235 (including)
Anyconnect_secure_mobility_client Cisco 3.0.5075 (including) 3.0.5075 (including)
Anyconnect_secure_mobility_client Cisco 3.0.5080 (including) 3.0.5080 (including)
Anyconnect_secure_mobility_client Cisco 3.0.09231 (including) 3.0.09231 (including)
Anyconnect_secure_mobility_client Cisco 3.0.09266 (including) 3.0.09266 (including)
Anyconnect_secure_mobility_client Cisco 3.0.09353 (including) 3.0.09353 (including)
Anyconnect_secure_mobility_client Cisco 3.1(60) (including) 3.1(60) (including)
Anyconnect_secure_mobility_client Cisco 3.1.0 (including) 3.1.0 (including)
Anyconnect_secure_mobility_client Cisco 3.1.02043 (including) 3.1.02043 (including)
Anyconnect_secure_mobility_client Cisco 3.1.05182 (including) 3.1.05182 (including)
Anyconnect_secure_mobility_client Cisco 3.1.05187 (including) 3.1.05187 (including)
Anyconnect_secure_mobility_client Cisco 3.1.06073 (including) 3.1.06073 (including)
Anyconnect_secure_mobility_client Cisco 3.1.07021 (including) 3.1.07021 (including)
Anyconnect_secure_mobility_client Cisco 4.0(48) (including) 4.0(48) (including)
Anyconnect_secure_mobility_client Cisco 4.0(64) (including) 4.0(64) (including)
Anyconnect_secure_mobility_client Cisco 4.0(2049) (including) 4.0(2049) (including)
Anyconnect_secure_mobility_client Cisco 4.0.0 (including) 4.0.0 (including)
Anyconnect_secure_mobility_client Cisco 4.0.00048 (including) 4.0.00048 (including)
Anyconnect_secure_mobility_client Cisco 4.0.00051 (including) 4.0.00051 (including)
Anyconnect_secure_mobility_client Cisco 4.1(8) (including) 4.1(8) (including)
Anyconnect_secure_mobility_client Cisco 4.1.0 (including) 4.1.0 (including)
Anyconnect_secure_mobility_client Cisco 4.2.0 (including) 4.2.0 (including)
Anyconnect_secure_mobility_client Cisco 4.2.04039 (including) 4.2.04039 (including)
Anyconnect_secure_mobility_client Cisco 4.3.0 (including) 4.3.0 (including)
Anyconnect_secure_mobility_client Cisco 4.3.00748 (including) 4.3.00748 (including)
Anyconnect_secure_mobility_client Cisco 4.3.01095 (including) 4.3.01095 (including)

References