CVE-2015-6322: Cisco AnyConnect Secure Mobility Client

Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move arbitrary files by leveraging the lack of source-path validation, aka Bug ID CSCuv48563.

Affected products

  • Cisco AnyConnect Secure Mobility Client: version 2.0.0343 only; version 2.1.0148 only; version 2.2.0133 only; version 2.2.0136 only; version 2.2.0140 only; version 2.3.0185 only; …

Published 2015-10-12. Last modified 2026-06-17.