Cisco AnyConnect Secure Mobility Client Downgrade Security Weaknesses
BID:54108
Info
Cisco AnyConnect Secure Mobility Client Downgrade Security Weaknesses
| Bugtraq ID: | 54108 |
| Class: | Design Error |
| CVE: |
CVE-2012-2494 CVE-2012-2495 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2012 12:00AM |
| Updated: | Mar 19 2015 08:41AM |
| Credit: | gwslabs.com via Zero Day Initiative and Cisco |
| Vulnerable: |
Cisco Secure Desktop 3.5.1077 Cisco Secure Desktop 3.5.841 Cisco Secure Desktop 3.4.2048 Cisco Secure Desktop 3.1.1 Cisco Secure Desktop 3.2 Cisco Secure Desktop 3.1.1.45 Cisco Secure Desktop 3.1.1.33 Cisco Secure Desktop 3.1 Cisco AnyConnect Secure Mobility Client 3.0.629 Cisco AnyConnect Secure Mobility Client 3.0 Cisco AnyConnect Secure Mobility Client 2.5.3046 Cisco AnyConnect Secure Mobility Client 2.5.3041 Cisco AnyConnect Secure Mobility Client 2.5 Cisco AnyConnect Secure Mobility Client 2.3.254 Cisco AnyConnect Secure Mobility Client 2.3.185 Cisco AnyConnect Secure Mobility Client 2.3 |
| Not Vulnerable: | |
Discussion
Cisco AnyConnect Secure Mobility Client Downgrade Security Weaknesses
Cisco AnyConnect Secure Mobility Client is prone to security weaknesses that may allow attackers to downgrade it to a prior software version.
Attackers can exploit these issues to cause the systems that have installed affected versions of the Cisco AnyConnect Secure Mobility client to download and install an older version of the client software. This older version of the client software may contain vulnerabilities which can be exploited by the attacker to perform further attacks.
These issues are tracked by Cisco Bug IDs CSCtw48681 and CSCtx74235.
Cisco AnyConnect Secure Mobility Client is prone to security weaknesses that may allow attackers to downgrade it to a prior software version.
Attackers can exploit these issues to cause the systems that have installed affected versions of the Cisco AnyConnect Secure Mobility client to download and install an older version of the client software. This older version of the client software may contain vulnerabilities which can be exploited by the attacker to perform further attacks.
These issues are tracked by Cisco Bug IDs CSCtw48681 and CSCtx74235.
Exploit / POC
Cisco AnyConnect Secure Mobility Client Downgrade Security Weaknesses
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco AnyConnect Secure Mobility Client Downgrade Security Weaknesses
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco AnyConnect Secure Mobility Client Downgrade Security Weaknesses
References:
References: