CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2015-0665 Cisco AnyConnect Secure Mobility Client Multiple Security Vulnerabilities

2016年10月31日 2771点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

Cisco AnyConnect is a VPN Client for multiple platforms.

The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities:
- The vulnerability is due to insufficient path traversal protections in certain IPC commands which could allow an attacker to write or overwrite arbitrary files on the filesystem.
- The vulnerability is due to missing input sanitization of certain IPC commands which may allow the attacker to write to arbitrary user-space memory.

Affected Versions:
Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier

漏洞危害

Successful exploitation will allow an attacker to execute arbitrary code, disclose sensitive information and overwrite arbitrary files on the filesystem.

解决方案

Cisco has confirmed the vulnerability however no patch is available as of now.

Workaround:
Administrators are advised to contact the vendor regarding future updates and releases.

0day

标签: 暂无
最后更新:2016年11月1日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me