7.2

CVE-2015-7600

Exploit

Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.

Data is provided by the National Vulnerability Database (NVD)
CiscoVpn Client Version5.0
CiscoVpn Client Version5.0.01
CiscoVpn Client Version5.0.01.0600
CiscoVpn Client Version5.0.2
CiscoVpn Client Version5.0.02.0090
CiscoVpn Client Version5.0.2.0090
CiscoVpn Client Version5.0.03.0530
CiscoVpn Client Version5.0.03.0560
CiscoVpn Client Version5.0.04.0300
CiscoVpn Client Version5.0.5
CiscoVpn Client Version5.0.05.0290
CiscoVpn Client Version5.0.6
CiscoVpn Client Version5.0.06.0160
CiscoVpn Client Version5.0.7
CiscoVpn Client Version5.0.7.0240
CiscoVpn Client Version5.0.7.0290
CiscoVpn Client Version5.0.07.0290
CiscoVpn Client Version5.0.07.0410
CiscoVpn Client Version5.0.07.0440
CiscoVpn Client Version5.0.7.0440
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.205
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C