Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-2494

EPSS 0.20% · P41
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-2494

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtw48681.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco AnyConnect Secure Mobility Client ‘WebLaunch’功能安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco AnyConnect Secure Mobility是一个安全的企业移动解决方案。 Cisco AnyConnect Secure Mobility Client 2.5 MR6之前的2.x版本和3.0 MR8之前的3.x版本中的WebLaunch功能中的VPN下载器的实现上存在漏洞,该漏洞源于未比较安装软件时间戳提供的软件时间戳。远程攻击者可利用该漏洞通过使用(1)ActiveX或(2)Java组件提供相应的旧软件的签署代码强制版本降级。又名 Bug ID CSCtw48681。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-2494

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-2494

登录查看更多情报信息。

Same Patch Batch · n/a · 2012-06-20 · 20 CVEs total

CVE-2012-0717IBM WebSphere Application Server授权问题漏洞
CVE-2012-2192IBM AIX ‘socketpair()’ 拒绝服务漏洞
CVE-2012-2180IBM DB2 DRDA模块拒绝服务漏洞
CVE-2012-2175IBM Lotus iNotes Upload Module ActiveX控件缓冲区溢出漏洞
CVE-2012-2174IBM Lotus Notes “notes” URI处理器任意代码执行漏洞
CVE-2012-2173IBM Security AppScan Source敏感信息漏洞
CVE-2012-2170IBM WebSphere Application Server信息泄漏漏洞
CVE-2012-2161IBM SPSS Data Collection跨站脚本漏洞
CVE-2012-2159IBM SPSS Data Collection开放重定向漏洞
CVE-2012-0720IBM WebSphere Application Server跨站脚本漏洞
CVE-2012-2493多个平台下的Cisco AnyConnect Secure Mobility Client任意代码执行漏洞
CVE-2012-0716IBM WebSphere Application Server跨站脚本漏洞
CVE-2012-3790Adiscon LogAnalyzer ‘highlight’参数跨站脚本漏洞
CVE-2011-5095OpenSSL ‘Diffie-Hellman key-exchange’安全漏洞
CVE-2011-1923PolarSSL安全绕过漏洞
CVE-2012-3063Cisco ACE安全绕过漏洞
CVE-2012-3058Cisco ASA/Catalyst ASASM拒绝服务漏洞
CVE-2012-2496Cisco AnyConnect Secure Mobility Client 代码注入漏洞
CVE-2012-2495Cisco AnyConnect Secure Mobility Client/Secure Desktop安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-2494

No comments yet


Leave a comment