Unrated severityNVD Advisory· Published Sep 26, 2015· Updated May 6, 2026
CVE-2015-6306
CVE-2015-6306
Description
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.
Affected products
1- cpe:2.3:a:cisco:anyconnect_secure_mobility_client:4.1.\(8\):*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securify.nl/advisory/SFY20150701/cisco_anyconnect_elevation_%20of_privileges_via_dmg_install_script.htmlnvdPatchThird Party Advisory
- packetstormsecurity.com/files/133685/Cisco-AnyConnect-DMG-Install-Script-Privilege-Escalation.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/38303/nvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2015/Sep/86nvdThird Party AdvisoryVDB Entry
- tools.cisco.com/security/center/viewAlert.xnvdVendor Advisory
- www.securitytracker.com/id/1033656nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/536534/100/0/threadednvd
News mentions
0No linked articles in our index yet.