CVE-2012-2499
published 2012-08-06CVE-2012-2499: The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which…
PriorityP422medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
0.53%
40.9th percentile
The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
| cisco | anyconnect_secure_mobility_client | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AnyConnect Secure Mobility Client IPsec Certificate Validation Vulnerability
vendor_cisco·2012-08-09·CVSS 5.8
CVE-2012-2499 [MEDIUM] CWE-310 Cisco AnyConnect Secure Mobility Client IPsec Certificate Validation Vulnerability
Cisco AnyConnect Secure Mobility Client IPsec Certificate Validation Vulnerability
Cisco AnyConnect Secure Mobility Client contains a vulnerability that could allow an unauthenticated, remote attacker to conduct man-in-the-middle attacks.
The vulnerability exists because the affected software does not perform certificate name checking in an X.509 certificate when the software is configured to use IPsec. An unauthenticated, remote attacker could convince a user to visit a malicious website using a certificate that may be displayed as valid for a legitimate site. If successful, the attacker could impersonate trusted servers, which an attacker could use to launch further attacks.
Cisco has confirmed this vulnerability and released software updates.
Exploits of this vulnerability may requ
GHSA
GHSA-fr9x-25xx-fj42: The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3
ghsa_unreviewed·2022-05-17
CVE-2012-2499 [MEDIUM] GHSA-fr9x-25xx-fj42: The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3
The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-08-06
Published