CVE-2015-4290

Description

The kernel extension in Cisco AnyConnect Secure Mobility Client 4.0(2049) on OS X allows local users to cause a denial of service (panic) via vectors involving contiguous memory locations, aka Bug ID CSCut12255.

Risk Information

Base Score
5.5
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.086

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Cisco AnyConnect Secure Mobility Client For Windows 4.0Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 4.0(2049)Windows
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2015-4290)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234