CVE-2012-2498
published 2012-08-06CVE-2012-2498: Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows…
PriorityP416medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
0.48%
38.2th percentile
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j35p-59jh-58v4: Cisco AnyConnect Secure Mobility Client 3
ghsa_unreviewed·2022-05-17
CVE-2012-2498 [MEDIUM] CWE-287 GHSA-j35p-59jh-58v4: Cisco AnyConnect Secure Mobility Client 3
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.
Cisco
Cisco AnyConnect Secure Mobility Client Man-in-the-Middle Attack Vulnerability
vendor_cisco·2012-08-09·CVSS 4.0
CVE-2012-2498 [MEDIUM] CWE-310 Cisco AnyConnect Secure Mobility Client Man-in-the-Middle Attack Vulnerability
Cisco AnyConnect Secure Mobility Client Man-in-the-Middle Attack Vulnerability
Cisco AnyConnect Secure Mobility Client contains a vulnerability that could allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks.
The vulnerability is due insufficient validation of certificates to be accepted by end users. An unauthenticated, remote attacker can exploit this vulnerability to impersonate trusted servers via crafted certificates. If successful, the attacker could launch further attacks.
Cisco has confirmed this vulnerability and released software updates.
Exploits of this vulnerability may require user interaction. An attacker could convince a user to visit a malicious website using a certificate that may be displayed as valid for a legitimate site. In addition, the
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-08-06
Published