PT-2012-4065 · Cisco · Cisco Secure Desktop+1

Published

2012-06-20

·

Updated

2012-06-21

·

CVE-2012-2495

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco AnyConnect Secure Mobility Client versions 3.x before 3.0 MR8 Cisco Secure Desktop versions prior to 3.6.6020
Description The issue allows remote attackers to force a version downgrade by using ActiveX or Java components to offer signed code that corresponds to an older software release.
Recommendations For Cisco AnyConnect Secure Mobility Client versions 3.x before 3.0 MR8, update to version 3.0 MR8 or later. For Cisco Secure Desktop versions prior to 3.6.6020, update to version 3.6.6020 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2495

Affected Products

Cisco Anyconnect Secure Mobility Client
Cisco Secure Desktop