4.3
CVSSv2

CVE-2012-2495

Published: 20/06/2012 Updated: 21/06/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x prior to 3.0 MR8 and Cisco Secure Desktop prior to 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote malicious users to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtx74235.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco anyconnect secure mobility client 3.0

cisco secure desktop 3.1.1.33

cisco secure desktop 3.4

cisco secure desktop 3.3

cisco secure desktop 3.5.2001

cisco secure desktop 3.2.1

cisco secure desktop 3.2

cisco secure desktop 3.1

cisco secure desktop 3.5.841

cisco secure desktop 3.4.2

cisco secure desktop 3.4.1

cisco secure desktop 3.4.2048

cisco secure desktop 3.1.1.45

cisco secure desktop 3.1.1.27

cisco secure desktop 3.1.1

cisco secure desktop 3.5

cisco secure desktop 3.5.1077

cisco secure desktop

Vendor Advisories

The Cisco AnyConnect Secure Mobility Client is affected by the following vulnerabilities: Cisco AnyConnect Secure Mobility Client VPN Downloader Arbitrary Code Execution Vulnerability Cisco AnyConnect Secure Mobility Client VPN Downloader Software Downgrade Vulnerability Cisco AnyConnect Secure Mobility Client and Cisco Secure Deskto ...