← Back

CVE-2016-6369

nvd nist
Published: Aug 25, 2016Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

Affected (57)

1 product
Anyconnect Secure Mobility Client
Configuration A
57 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 2.0.0343
Version 2.1.0148
Version 2.2.0133
Version 2.2.0136
Version 2.2.0140
Version 2.3.0185
Version 2.3.0254
Version 2.3.1003
Version 2.3.2016
Version 2.4.0202
Version 2.4.1012
Version 2.5.0217
Version 2.5.2006
Version 2.5.2010
Version 2.5.2011
Version 2.5.2014
Version 2.5.2017
Version 2.5.2018
Version 2.5.2019
Version 2.5.3041
Version 2.5.3046
Version 2.5.3051
Version 2.5.3054
Version 2.5.3055
Version 2.5_base
Version 3.0.0629
Version 3.0.09231
Version 3.0.09266
Version 3.0.09353
Version 3.0.0
Version 3.0.1047
Version 3.0.2052
Version 3.0.3050
Version 3.0.3054
Version 3.0.4235
Version 3.0.5075
Version 3.0.5080
Version 3.1.02043
Version 3.1.05182
Version 3.1.05187
Version 3.1.06073
Version 3.1.07021
Version 3.1.0
Version 3.1(60)
Version 4.0.00048
Version 4.0.00051
Version 4.0.0
Version 4.0(2049)
Version 4.0(48)
Version 4.0(64)
Version 4.1.0
Version 4.1(8)
Version 4.2.04039
Version 4.2.0
Version 4.3.00748
Version 4.3.01095
Version 4.3.0

Related CWEs

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.