CVE-2012-2499

Description

The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.

Risk Information

Base Score
5.9
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.137

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2012-1370,CVE-2012-2499,CVE-2012-2500 are affected in Cisco AnyConnect Secure Mobility Client For Windows 3.0.07059Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.0629Windows
Multiple Vulnerabilities are affected in Any Connect (Microsoft Store) 3.0.07059Windows
CVE-2012-2499NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-338372Cisco AnyConnect Secure Mobility Client (4.10.08029) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234