CVE-2012-4655
Summary
| CVE | CVE-2012-4655 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-24 17:55:07 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug IDs CSCtz76128 and CSCtz78204. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Desktop | 3.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1.27 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1.33 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1.45 | All | All | All |
| Application | Cisco | Secure Desktop | 3.2 | All | All | All |
| Application | Cisco | Secure Desktop | 3.2.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.3 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4.2 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4.2048 | All | All | All |
| Application | Cisco | Secure Desktop | 3.5 | All | All | All |
| Application | Cisco | Secure Desktop | 3.5.1077 | All | All | All |
| Application | Cisco | Secure Desktop | 3.5.2001 | All | All | All |
| Application | Cisco | Secure Desktop | 3.5.2008 | All | All | All |
| Application | Cisco | Secure Desktop | 3.5.841 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.1001 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.181 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.185 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.2002 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.3002 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.4021 | All | All | All |
| Application | Cisco | Secure Desktop | 3.6.5005 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA50669 - Cisco Secure Desktop WebLaunch Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Security Advisory: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Secure Desktop CVE-2012-4655 Arbitrary Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.