ID

VAR-201505-0197


CVE

CVE-2015-0755


TITLE

Cisco AnyConnect Secure Mobility Client Distributed by Cisco Identity Services Engine for Posture Vulnerability in obtaining privileges in module

Trust: 0.8

sources: JVNDB: JVNDB-2015-002870

DESCRIPTION

The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797. Vendors report this vulnerability Bug ID CSCut05797 Published as. Supplementary information : CWE Vulnerability types by CWE-284: Improper Access Control ( Improper access control ) Has been identified. http://cwe.mitre.org/data/definitions/284.htmlLocal users may gain privileges via unspecified commands. An attacker can exploit this issue to gain elevated privileges on an affected device. Cisco AnyConnect Secure Mobility Client is a next-generation VPN client. This client enables remote users to securely connect to Cisco ASA 5500 devices through SSL VPN

Trust: 1.98

sources: NVD: CVE-2015-0755 // JVNDB: JVNDB-2015-002870 // BID: 74868 // VULHUB: VHN-78701

AFFECTED PRODUCTS

vendor:ciscomodel:anyconnect secure mobility clientscope:eqversion:4.0\(64\)

Trust: 1.6

vendor:ciscomodel:anyconnect secure mobility clientscope:eqversion:4.0(64)

Trust: 1.1

vendor:ciscomodel:identity services engine softwarescope:eqversion:0

Trust: 0.3

sources: BID: 74868 // JVNDB: JVNDB-2015-002870 // CNNVD: CNNVD-201505-584 // NVD: CVE-2015-0755

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0755
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0755
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201505-584
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78701
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0755
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-78701
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78701 // JVNDB: JVNDB-2015-002870 // CNNVD: CNNVD-201505-584 // NVD: CVE-2015-0755

PROBLEMTYPE DATA

problemtype:CWE-284

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-78701 // JVNDB: JVNDB-2015-002870 // NVD: CVE-2015-0755

THREAT TYPE

local

Trust: 0.9

sources: BID: 74868 // CNNVD: CNNVD-201505-584

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201505-584

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002870

PATCH

title:39018url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39018

Trust: 0.8

sources: JVNDB: JVNDB-2015-002870

EXTERNAL IDS

db:NVDid:CVE-2015-0755

Trust: 2.8

db:SECTRACKid:1032424

Trust: 1.1

db:JVNDBid:JVNDB-2015-002870

Trust: 0.8

db:CNNVDid:CNNVD-201505-584

Trust: 0.7

db:SECUNIAid:64671

Trust: 0.6

db:BIDid:74868

Trust: 0.4

db:VULHUBid:VHN-78701

Trust: 0.1

sources: VULHUB: VHN-78701 // BID: 74868 // JVNDB: JVNDB-2015-002870 // CNNVD: CNNVD-201505-584 // NVD: CVE-2015-0755

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39018

Trust: 2.0

url:http://www.securitytracker.com/id/1032424

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0755

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0755

Trust: 0.8

url:http://secunia.com/advisories/64671

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps11640/

Trust: 0.3

sources: VULHUB: VHN-78701 // BID: 74868 // JVNDB: JVNDB-2015-002870 // CNNVD: CNNVD-201505-584 // NVD: CVE-2015-0755

CREDITS

Cisco

Trust: 0.3

sources: BID: 74868

SOURCES

db:VULHUBid:VHN-78701
db:BIDid:74868
db:JVNDBid:JVNDB-2015-002870
db:CNNVDid:CNNVD-201505-584
db:NVDid:CVE-2015-0755

LAST UPDATE DATE

2024-11-23T22:45:57.605000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78701date:2017-01-04T00:00:00
db:BIDid:74868date:2015-05-27T00:00:00
db:JVNDBid:JVNDB-2015-002870date:2015-06-03T00:00:00
db:CNNVDid:CNNVD-201505-584date:2015-06-01T00:00:00
db:NVDid:CVE-2015-0755date:2024-11-21T02:23:39.530

SOURCES RELEASE DATE

db:VULHUBid:VHN-78701date:2015-05-29T00:00:00
db:BIDid:74868date:2015-05-27T00:00:00
db:JVNDBid:JVNDB-2015-002870date:2015-06-03T00:00:00
db:CNNVDid:CNNVD-201505-584date:2015-05-29T00:00:00
db:NVDid:CVE-2015-0755date:2015-05-29T15:59:09.327