CVE-2016-6369

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
ciscoanyconnect_secure_mobility_client
2.0.0343
ciscoanyconnect_secure_mobility_client
2.1.0148
ciscoanyconnect_secure_mobility_client
2.2.0133
ciscoanyconnect_secure_mobility_client
2.2.0136
ciscoanyconnect_secure_mobility_client
2.2.0140
ciscoanyconnect_secure_mobility_client
2.3.0185
ciscoanyconnect_secure_mobility_client
2.3.0254
ciscoanyconnect_secure_mobility_client
2.3.1003
ciscoanyconnect_secure_mobility_client
2.3.2016
ciscoanyconnect_secure_mobility_client
2.4.0202
ciscoanyconnect_secure_mobility_client
2.4.1012
ciscoanyconnect_secure_mobility_client
2.5.0217
ciscoanyconnect_secure_mobility_client
2.5.2006
ciscoanyconnect_secure_mobility_client
2.5.2010
ciscoanyconnect_secure_mobility_client
2.5.2011
ciscoanyconnect_secure_mobility_client
2.5.2014
ciscoanyconnect_secure_mobility_client
2.5.2017
ciscoanyconnect_secure_mobility_client
2.5.2018
ciscoanyconnect_secure_mobility_client
2.5.2019
ciscoanyconnect_secure_mobility_client
2.5.3041
ciscoanyconnect_secure_mobility_client
2.5.3046
ciscoanyconnect_secure_mobility_client
2.5.3051
ciscoanyconnect_secure_mobility_client
2.5.3054
ciscoanyconnect_secure_mobility_client
2.5.3055
ciscoanyconnect_secure_mobility_client
2.5_base:_base
ciscoanyconnect_secure_mobility_client
3.0.0
ciscoanyconnect_secure_mobility_client
3.0.0629
ciscoanyconnect_secure_mobility_client
3.0.1047
ciscoanyconnect_secure_mobility_client
3.0.2052
ciscoanyconnect_secure_mobility_client
3.0.3050
ciscoanyconnect_secure_mobility_client
3.0.3054
ciscoanyconnect_secure_mobility_client
3.0.4235
ciscoanyconnect_secure_mobility_client
3.0.5075
ciscoanyconnect_secure_mobility_client
3.0.5080
ciscoanyconnect_secure_mobility_client
3.0.09231
ciscoanyconnect_secure_mobility_client
3.0.09266
ciscoanyconnect_secure_mobility_client
3.0.09353
ciscoanyconnect_secure_mobility_client
3.1\(60\)
ciscoanyconnect_secure_mobility_client
3.1.0
ciscoanyconnect_secure_mobility_client
3.1.02043
ciscoanyconnect_secure_mobility_client
3.1.05182
ciscoanyconnect_secure_mobility_client
3.1.05187
ciscoanyconnect_secure_mobility_client
3.1.06073
ciscoanyconnect_secure_mobility_client
3.1.07021
ciscoanyconnect_secure_mobility_client
4.0\(48\)
ciscoanyconnect_secure_mobility_client
4.0\(64\)
ciscoanyconnect_secure_mobility_client
4.0\(2049\)
ciscoanyconnect_secure_mobility_client
4.0.0
ciscoanyconnect_secure_mobility_client
4.0.00048
ciscoanyconnect_secure_mobility_client
4.0.00051
ciscoanyconnect_secure_mobility_client
4.1\(8\)
ciscoanyconnect_secure_mobility_client
4.1.0
ciscoanyconnect_secure_mobility_client
4.2.0
ciscoanyconnect_secure_mobility_client
4.2.04039
ciscoanyconnect_secure_mobility_client
4.3.0
ciscoanyconnect_secure_mobility_client
4.3.00748
ciscoanyconnect_secure_mobility_client
4.3.01095
𝑥
= Vulnerable software versions
Common Weakness Enumeration