Vulnerabilities > Cisco > VPN Client

DATE CVE VULNERABILITY TITLE RISK
2015-10-06 CVE-2015-7600 Permissions, Privileges, and Access Controls vulnerability in Cisco VPN Client
Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.
local
low complexity
cisco CWE-264
7.2
2013-01-17 CVE-2012-5429 Local Denial of Service vulnerability in Cisco VPN Client for Windows
The VPN driver in Cisco VPN Client on Windows does not properly interact with the kernel, which allows local users to cause a denial of service (kernel fault and system crash) via a crafted application, aka Bug ID CSCuc81669.
local
low complexity
cisco microsoft
4.6
2012-09-16 CVE-2012-3052 Unspecified vulnerability in Cisco VPN Client
Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.
local
cisco
6.9
2011-07-07 CVE-2011-2678 Local Security vulnerability in Cisco VPN Client 5.0.7.0240/5.0.7.0290
The Cisco VPN Client 5.0.7.0240 and 5.0.7.0290 on 64-bit Windows platforms uses weak permissions (NT AUTHORITY\INTERACTIVE:F) for cvpnd.exe, which allows local users to gain privileges by replacing this executable file with an arbitrary program, aka Bug ID CSCtn50645.
local
low complexity
cisco microsoft
6.8
2009-12-01 CVE-2009-4118 Local Denial of Service vulnerability in Cisco VPN Client for Windows 'StartServiceCtrlDispatche'
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.
local
low complexity
cisco
2.1
2008-11-18 CVE-2008-5121 Permissions, Privileges, and Access Controls vulnerability in Citrix Deterministic Network Enhancer 2.21.7.223/3.21.7.17464
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.
local
low complexity
citrix bluecoat cisco safenet CWE-264
7.2
2008-01-17 CVE-2008-0324 Resource Management Errors vulnerability in Cisco VPN Client 5.0.2.0090
Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.
local
low complexity
cisco CWE-399
4.9
2007-08-18 CVE-2007-4415 Local Privilege Escalation vulnerability in Cisco VPN Client 5.0.01.0600
Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.
local
low complexity
cisco
6.8
2007-08-18 CVE-2007-4414 Local Privilege Escalation vulnerability in Cisco VPN Client for Windows
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.
local
low complexity
cisco
6.8
2007-03-16 CVE-2007-1467 Cross-Site Scripting vulnerability in Multiple Cisco Products Online Help
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.
network
cisco
3.5