CVE-2012-2495
published 2012-06-20CVE-2012-2495: The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.40%
69.3th percentile
The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtx74235.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | secure_desktop | <= 3.5.2008 | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jp4v-v2ww-7m2h: The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3
ghsa_unreviewed·2022-05-17
CVE-2012-2495 [MEDIUM] CWE-20 GHSA-jp4v-v2ww-7m2h: The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3
The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtx74235.
Cisco
Cisco AnyConnect Secure Mobility Client and Secure Desktop WebLaunch Software Downgrade Vulnerability
vendor_cisco·2012-06-20·CVSS 4.3
CVE-2012-2495 [MEDIUM] Cisco AnyConnect Secure Mobility Client and Secure Desktop WebLaunch Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client and Secure Desktop WebLaunch Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client and Secure Desktop contain a vulnerability that could allow an unauthenticated, remote attacker to replace software components on a targeted system.
The vulnerability exists because the affected software performs insufficient validation of user-supplied input. An unauthenticated, remote attacker could exploit the vulnerability by convincing the user to view a malicious website. If successful, the attacker could cause the affected software to be downgraded to a prior version.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
To exploit the vulnerability, the attacker may provide a link that directs a user t
Cisco
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
vendor_cisco·2012-06-20·CVSS 9.3
CVE-2012-2493 [CRITICAL] CWE-399 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities:
Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerability
Cisco AnyConnect Secure Mobility Client VPN Downloader Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client and Cisco Secure Desktop Hostscan Downloader Software Downgrade Vulnerability
Cisco AnyConnect Secure Mobility Client 64-bit Java VPN Downloader Arbitrary Code Execution Vulnerability
Cisco Secure Desktop Arbitrary Code Execution Vulnerability
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available. This advisory is available at the foll
Cisco
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
vendor_cisco
CVE-2012-2495 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
CVE-2012-2495: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client
The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities: Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerability Cisco AnyConnect Secure Mobility Client VPN Downloader Software Downgrade Vulnerability Cisco AnyConnect Secure Mobility Client and Cisco Secure Desktop Hostscan Downloader Software Downgrade Vulnerability Cisco AnyConnect Secure Mobility Client 64-bit Java VPN Downloader Arbitrary Code Execution Vulnerability Cisco Secure Desktop Arbitrary Code Execution Vulnerability Cisco has released software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCtw47523, CSCtw48681, CSCtx74235, CSCtw47523, CSCtw48681
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-06-20
Published