CyberSec.Space Logo
返回 CVE 浏览器

CVE-2012-2493

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1100%
EPSS Percentile25.94th
Published2012年6月20日
Last Modified2026年4月29日

Vulnerability Description

The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug ID CSCtw47523.

Affected Platforms (CPE)

📦
Cisco

Anyconnect Secure Mobility Client

= 2.0
📦
Cisco

Anyconnect Secure Mobility Client

= 2.1
📦
Cisco

Anyconnect Secure Mobility Client

= 2.2
📦
Cisco

Anyconnect Secure Mobility Client

= 2.2.128
📦
Cisco

Anyconnect Secure Mobility Client

= 2.2.133
📦
Cisco

Anyconnect Secure Mobility Client

= 2.2.136
📦
Cisco

Anyconnect Secure Mobility Client

= 2.2.140
📦
Cisco

Anyconnect Secure Mobility Client

= 2.3
📦
Cisco

Anyconnect Secure Mobility Client

= 2.3.185
📦
Cisco

Anyconnect Secure Mobility Client

= 2.3.254
📦
Cisco

Anyconnect Secure Mobility Client

= 2.3.2016
📦
Cisco

Anyconnect Secure Mobility Client

= 2.4
📦
Cisco

Anyconnect Secure Mobility Client

= 2.4.0202
📦
Cisco

Anyconnect Secure Mobility Client

= 2.4.1012
📦
Cisco

Anyconnect Secure Mobility Client

= 2.5
📦
Cisco

Anyconnect Secure Mobility Client

= 3.0

References & Advisories

相关漏洞威胁