Directory traversal vulnerability in Cisco AnyConnect Secure Mobility Client 4.0(2049) allows remote head-end systems to write to arbitrary files via a crafted configuration attribute, aka Bug ID CSCut93920.
http://www.securitytracker.com/id/1033173
http://tools.cisco.com/security/center/viewAlert.x?alertId=40175