Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-2495

EPSS 0.21% · P44
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-2495

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed code that corresponds to an older software release, aka Bug ID CSCtx74235.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco AnyConnect Secure Mobility Client/Secure Desktop安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco AnyConnect Secure Mobility是一个安全的企业移动解决方案。 Cisco AnyConnect Secure Mobility Client 3.0 MR8之前的3.x版本和Cisco Secure Desktop 3.6.6020之前版本中的HostScan downloader的实现上存在漏洞,该漏洞源于未比较安装软件时间戳提供的软件时间戳。远程攻击者可利用该漏洞通过使用(1)ActiveX或(2)Java组件提供相应的旧软件的签署代码强制版本降级。又名Bug ID
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-2495

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-2495

Please Login to view more intelligence information

Same Patch Batch · n/a · 2012-06-20 · 20 CVEs total

CVE-2012-0717IBM WebSphere Application Server授权问题漏洞
CVE-2012-2192IBM AIX ‘socketpair()’ 拒绝服务漏洞
CVE-2012-2180IBM DB2 DRDA模块拒绝服务漏洞
CVE-2012-2175IBM Lotus iNotes Upload Module ActiveX控件缓冲区溢出漏洞
CVE-2012-2174IBM Lotus Notes “notes” URI处理器任意代码执行漏洞
CVE-2012-2173IBM Security AppScan Source敏感信息漏洞
CVE-2012-2170IBM WebSphere Application Server信息泄漏漏洞
CVE-2012-2161IBM SPSS Data Collection跨站脚本漏洞
CVE-2012-2159IBM SPSS Data Collection开放重定向漏洞
CVE-2012-0720IBM WebSphere Application Server跨站脚本漏洞
CVE-2012-2493多个平台下的Cisco AnyConnect Secure Mobility Client任意代码执行漏洞
CVE-2012-0716IBM WebSphere Application Server跨站脚本漏洞
CVE-2012-3790Adiscon LogAnalyzer ‘highlight’参数跨站脚本漏洞
CVE-2011-5095OpenSSL ‘Diffie-Hellman key-exchange’安全漏洞
CVE-2011-1923PolarSSL安全绕过漏洞
CVE-2012-3063Cisco ACE安全绕过漏洞
CVE-2012-3058Cisco ASA/Catalyst ASASM拒绝服务漏洞
CVE-2012-2496Cisco AnyConnect Secure Mobility Client 代码注入漏洞
CVE-2012-2494Cisco AnyConnect Secure Mobility Client ‘WebLaunch’功能安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-2495

No comments yet


Leave a comment