CVE-2012-2498

Description

Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

Risk Information

Base Score
5.9
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.103

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client For Windows 3.0.08066Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.0629Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.07059Windows
Vulnerabilities CVE-2012-2498,CVE-2013-1172,CVE-2013-1173 are affected in Any Connect (Microsoft Store) 3.0.08066Windows
Vulnerabilities CVE-2011-2040,CVE-2012-2494,CVE-2012-2495,CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.0629Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.07059Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.08057Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.08066Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.0629Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.07059Mac
Vulnerabilities CVE-2012-2498 are affected in Cisco AnyConnect Secure Mobility Client for Mac 3.0.08066Mac
Improper Authentication Vulnerability (CVE-2012-2498)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029
PATCH-606843Cisco AnyConnect Secure Mobility Client for Mac 4.10.08029

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234