7.2

CVE-2015-7600

Exploit

Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoVpn Client Version5.0
CiscoVpn Client Version5.0.01
CiscoVpn Client Version5.0.01.0600
CiscoVpn Client Version5.0.2
CiscoVpn Client Version5.0.02.0090
CiscoVpn Client Version5.0.2.0090
CiscoVpn Client Version5.0.03.0530
CiscoVpn Client Version5.0.03.0560
CiscoVpn Client Version5.0.04.0300
CiscoVpn Client Version5.0.5
CiscoVpn Client Version5.0.05.0290
CiscoVpn Client Version5.0.6
CiscoVpn Client Version5.0.06.0160
CiscoVpn Client Version5.0.7
CiscoVpn Client Version5.0.7.0240
CiscoVpn Client Version5.0.7.0290
CiscoVpn Client Version5.0.07.0290
CiscoVpn Client Version5.0.07.0410
CiscoVpn Client Version5.0.07.0440
CiscoVpn Client Version5.0.7.0440
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.205
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C