Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2015-7600

Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.

  • Published: Oct 6, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-7600
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.2
  • AV:L/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
cisco / vpn_client 5.0.05.0290 5.0.05.0290.x
cisco / vpn_client 5.0.7.0290 5.0.7.0290.x
cisco / vpn_client 5.0 5.0.x
cisco / vpn_client 5.0.04.0300 5.0.04.0300.x
cisco / vpn_client 5.0.02.0090 5.0.02.0090.x
cisco / vpn_client 5.0.06.0160 5.0.06.0160.x
cisco / vpn_client 5.0.5 5.0.5.x
cisco / vpn_client 5.0.2.0090 5.0.2.0090.x
cisco / vpn_client 5.0.07.0410 5.0.07.0410.x
cisco / vpn_client 5.0.7.0240 5.0.7.0240.x
cisco / vpn_client 5.0.07.0440 5.0.07.0440.x
cisco / vpn_client 5.0.03.0560 5.0.03.0560.x
cisco / vpn_client 5.0.6 5.0.6.x
cisco / vpn_client 5.0.03.0530 5.0.03.0530.x
cisco / vpn_client 5.0.7 5.0.7.x
cisco / vpn_client 5.0.01 5.0.01.x
cisco / vpn_client 5.0.07.0290 5.0.07.0290.x
cisco / vpn_client 5.0.2 5.0.2.x
cisco / vpn_client 5.0.01.0600 5.0.01.0600.x
cisco / vpn_client 5.0.7.0440 5.0.7.0440.x