CVE-2015-6306

Cisco Anyconnect Secure Mobility Client - Access Control

Title source: rule

Description

Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.

Exploits (1)

exploitdb WORKING POC
by Yorick Koster · clocalosx
https://www.exploit-db.com/exploits/38303

Scores

EPSS 0.0355
EPSS Percentile 87.7%

Details

CWE
CWE-264
Status published
Products (1)
cisco/anyconnect_secure_mobility_client 4.1.\(8\)
Published Sep 26, 2015
Tracked Since Feb 18, 2026