CVE-2012-2496

Description

A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on 64-bit Linux platforms does not properly restrict use of Java components, which allows remote attackers to execute arbitrary code via a crafted web site, aka Bug ID CSCty45925.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.113

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-2495,CVE-2012-2496 are affected in Cisco AnyConnect Secure Mobility Client For Windows 3.0Windows
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client For Cisco AnyConnect Secure Mobility ClientNCM
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability For Cisco AnyConnect Secure Mobility ClientNCM
Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client For Cisco Secure DesktopNCM
Improper Input Validation Vulnerability (CVE-2012-2496)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-1702090Security Update for Cisco Secure Desktop 3.1(3103)
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234