CVE-2012-2493
Description
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug ID CSCtw47523.
Risk Information
Base Score
8.4
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.283
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.0 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.1 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.128 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.133 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.136 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.2.140 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3.185 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3.2016 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.3.254 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.4.0202 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.4.1012 | Windows |
| Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 2.5 | Windows |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.0 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.1 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.128 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.133 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.136 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.140 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3.185 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3.2016 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3.254 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.4 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.4.0202 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.4.1012 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.5 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.0 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.1 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.128 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.133 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.136 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.2.140 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3.185 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3.2016 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.3.254 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.4.0202 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.4.1012 | Mac |
| Vulnerabilities CVE-2011-2040,CVE-2012-2493,CVE-2012-2494,CVE-2013-5559 are affected in Cisco AnyConnect Secure Mobility Client for Mac 2.5 | Mac |
| Improper Input Validation Vulnerability (CVE-2012-2493) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
| PATCH-606843 | Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029 |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234