The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Computer vulnerabilities of AnyConnect VPN Client

Cisco AnyConnect VPN Client: privilege escalation via vpnclient.ini
A local attacker can alter the vpnclient.ini file of Cisco AnyConnect VPN Client, in order to escalate his privileges...
CVE-2015-7600, VIGILANCE-VUL-18052
Cisco AnyConnect Secure Mobility Client: privilege escalation via DLL
An attacker can make Cisco AnyConnect Secure Mobility Client loads and run arbitrary DLL, in order to escalate his privileges...
41136, CSCuv01279, CVE-2015-6305, VIGILANCE-VUL-17958
Cisco AnyConnect Secure Mobility Client: directory traversal
An attacker can traverse directories of Cisco AnyConnect Secure Mobility Client, in order to write a file outside the service root path...
40175, CSCut93920, CVE-2015-4289, VIGILANCE-VUL-17550
Cisco AnyConnect Secure Mobility Client: denial of service via Mac OS X
A local attacker can stop the Mac OS X kernel via Cisco AnyConnect Secure Mobility Client, in order to trigger a denial of service...
40176, CSCut12255, CVE-2015-4290, VIGILANCE-VUL-17538
Cisco AnyConnect VPN Client for Windows: privilege escalation via program install
An attacker can create an INF file for Cisco AnyConnect VPN Client for Windows, in order to make it run any program with the privileges of the SYSTEM account...
39466, CVE-2015-4211, VIGILANCE-VUL-17218
OpenSSL: use after free via DTLS
An attacker can force the usage of a freed memory area via DTLS in OpenSSL, in order to trigger a denial of service, and possibly to execute code...
1961569, 9010038, 9010039, BSA-2015-006, c05184351, CERTFR-2015-AVI-257, cisco-sa-20150612-openssl, CVE-2014-8176, DSA-2019-197, DSA-3287-1, HPSBHF03613, NetBSD-SA2015-008, NTAP-20150616-0001, openSUSE-SU-2015:1277-1, PAN-SA-2016-0020, PAN-SA-2016-0028, RHSA-2015:1115-01, SA98, SB10122, SOL16920, USN-2639-1, VIGILANCE-VUL-17118
OpenSSL: four vulnerabilities
An attacker can use several vulnerabilities of OpenSSL...
1450666, 1610582, 1647054, 1961111, 1961569, 1964113, 1964766, 1966038, 1970103, 1972125, 9010038, 9010039, BSA-2015-006, bulletinjul2015, c04760669, c05184351, c05353965, CERTFR-2015-AVI-257, CERTFR-2015-AVI-431, CERTFR-2016-AVI-128, CERTFR-2016-AVI-303, cisco-sa-20150612-openssl, cpuapr2017, cpuoct2017, CTX216642, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, DSA-2019-197, DSA-2020-062, DSA-3287-1, FEDORA-2015-10047, FEDORA-2015-10108, FreeBSD-SA-15:10.openssl, HPSBGN03678, HPSBHF03613, HPSBUX03388, JSA10694, JSA10733, NetBSD-SA2015-008, NTAP-20150616-0001, openSUSE-SU-2015:1139-1, openSUSE-SU-2015:1277-1, openSUSE-SU-2015:2243-1, openSUSE-SU-2016:0640-1, PAN-SA-2016-0020, PAN-SA-2016-0028, RHSA-2015:1115-01, RHSA-2015:1197-01, SA40002, SA98, SB10122, SOL16898, SOL16913, SOL16915, SOL16938, SSA:2015-162-01, SSRT102180, SUSE-SU-2015:1143-1, SUSE-SU-2015:1150-1, SUSE-SU-2015:1181-1, SUSE-SU-2015:1181-2, SUSE-SU-2015:1182-2, SUSE-SU-2015:1183-1, SUSE-SU-2015:1183-2, SUSE-SU-2015:1184-1, SUSE-SU-2015:1184-2, SUSE-SU-2015:1185-1, TNS-2015-07, TSB16728, USN-2639-1, VIGILANCE-VUL-17117
OpenSSL: use after free via NewSessionTicket
An attacker, who own a malicious TLS server, can send the NewSessionTicket message, to force the usage of a freed memory area in a client linked to OpenSSL, in order to trigger a denial of service, and possibly to execute code...
1961569, 1964113, 1970103, 2003480, 2003620, 2003673, 9010038, 9010039, bulletinjul2015, c04760669, c05184351, c05353965, CERTFR-2015-AVI-431, CERTFR-2016-AVI-128, CERTFR-2016-AVI-303, cisco-sa-20150612-openssl, cpuapr2017, cpuoct2016, cpuoct2017, CTX216642, CVE-2015-1791, DSA-2019-197, DSA-2020-062, DSA-3287-1, FEDORA-2015-10047, FEDORA-2015-10108, FreeBSD-SA-15:10.openssl, HPSBGN03678, HPSBHF03613, HPSBUX03388, JSA10694, JSA10733, NetBSD-SA2015-008, NTAP-20150616-0001, openSUSE-SU-2015:1139-1, openSUSE-SU-2016:0640-1, PAN-SA-2016-0020, PAN-SA-2016-0028, RHSA-2015:1115-01, SA40002, SA98, SB10122, SOL16914, SSA:2015-162-01, SSRT102180, SUSE-SU-2015:1143-1, SUSE-SU-2015:1150-1, SUSE-SU-2015:1182-2, SUSE-SU-2015:1184-1, SUSE-SU-2015:1184-2, SUSE-SU-2015:1185-1, TSB16728, USN-2639-1, VIGILANCE-VUL-17062
Cisco AnyConnect: privilege escalation via vpnagent
An attacker can run vpnagent of Cisco AnyConnect with a crafted command line, in order to escalate his privileges...
39158, CSCus86790, CVE-2015-0761, VIGILANCE-VUL-17046
Cisco AnyConnect Secure Mobility Client: privilege escalation via Identity Services Engine
An attacker can use Identity Services Engine of Cisco AnyConnect Secure Mobility Client, in order to escalate his privileges...
39018, CSCut05797, CVE-2015-0755, VIGILANCE-VUL-17024
Our database contains other pages. You can request a free trial to read them.