CVE-2012-2494
published 2012-06-20CVE-2012-2494: The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.40%
69.3th percentile
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtw48681.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco9.3CRITICAL
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AnyConnect Secure Mobility Client Software Downgrade Vulnerability
vendor_cisco·2012-06-20·CVSS 4.3
CVE-2012-2494 [MEDIUM] Cisco AnyConnect Secure Mobility Client Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client contains a vulnerability that could allow an unauthenticated, remote attacker to replace software components.
The vulnerability is due to improper sanitization of user-supplied input by the affected software's download feature. An unauthenticated, remote attacker could exploit this vulnerability by persuading a user to view a malicious website. If successful, the attacker could cause the affected software to download and install an older version of the software.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading la
Cisco
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
vendor_cisco·2012-06-20·CVSS 9.3
CVE-2012-2493 [CRITICAL] CWE-399 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities:
Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerability
Cisco AnyConnect Secure Mobility Client VPN Downloader Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client and Cisco Secure Desktop Hostscan Downloader Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client 64-bit Java VPN Downloader Arbitrary Code Execution Vulnerability
Cisco Secure Desktop Arbitrary Code Execution Vulnerability
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available. This advisory is available at the foll
Red Hat
kernel: taskstats io infoleak
vendor_redhat·2011-06-21·CVSS 2.1
CVE-2011-2494 [LOW] kernel: taskstats io infoleak
kernel: taskstats io infoleak
kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not provide support for the Taskstats interface. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1479.html, https://rhn.redhat.com/errata/RHSA-2011-1465.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Cisco
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
vendor_cisco
CVE-2012-2494 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
CVE-2012-2494: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities: Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerability Cisco AnyConnect Secure Mobility Client VPN Downloader Software Downgrade Vulnerability Cisco AnyConnect Secure Mobility Client and Cisco Secure Desktop Hostscan Downloader Software Downgrade Vulnerability Cisco AnyConnect Secure Mobility Client 64-bit Java VPN Downloader Arbitrary Code Execution Vulnerability Cisco Secure Desktop Arbitrary Code Execution Vulnerability Cisco has released software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCtw47523, CSCtw48681, CSCtx74235, CSCtw47523, CSCtw48681
GHSA
GHSA-52cj-532j-rfcv: The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2
ghsa_unreviewed·2022-05-17
CVE-2012-2494 [MEDIUM] CWE-20 GHSA-52cj-532j-rfcv: The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtw48681.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-06-20
Published