2
CVSSv3

CVE-2012-2495

CVSSv4: NA | CVSSv3: 2 | CVSSv2: 4.3 | VMScore: 530 | EPSS: 0.00215 | KEV: Not Included
Published: 20/06/2012 Updated: 21/11/2024

Vulnerability Summary

The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x prior to 3.0 MR8 and Cisco Secure Desktop prior to 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote malicious users to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtx74235.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco anyconnect secure mobility client 3.0

cisco secure desktop

cisco secure desktop 3.1

cisco secure desktop 3.1.1

cisco secure desktop 3.1.1.27

cisco secure desktop 3.1.1.33

cisco secure desktop 3.1.1.45

cisco secure desktop 3.2

cisco secure desktop 3.2.1

cisco secure desktop 3.3

cisco secure desktop 3.4

cisco secure desktop 3.4.1

cisco secure desktop 3.4.2

cisco secure desktop 3.4.2048

cisco secure desktop 3.5

cisco secure desktop 3.5.841

cisco secure desktop 3.5.1077

cisco secure desktop 3.5.2001

Vendor Advisories

The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities: Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerability Cisco AnyConnect Secure Mobility Client VPN Downloader Software Downgrade Vulnerability Cisco AnyConnect Secure Mobility Client and Cisco Secure Deskto ...