VulnerabilityModified
CVE-2007-4414
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.
MEDIUM 6.8EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- cisco/vpn client
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/26459Vendor Advisory
- http://securitytracker.com/id?1018573
- http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtml
- http://www.securityfocus.com/bid/25332Patch
- http://www.vupen.com/english/advisories/2007/2903
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36029
- http://secunia.com/advisories/26459Vendor Advisory
- http://securitytracker.com/id?1018573
- http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtml
- http://www.securityfocus.com/bid/25332Patch
- http://www.vupen.com/english/advisories/2007/2903
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36029
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.