Cisco AnyConnect Secure Mobility Client CVE-2012-2498 Certificate Validation Vulnerability
BID:54847
Info
Cisco AnyConnect Secure Mobility Client CVE-2012-2498 Certificate Validation Vulnerability
| Bugtraq ID: | 54847 |
| Class: | Design Error |
| CVE: |
CVE-2012-2498 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2012 12:00AM |
| Updated: | Aug 07 2012 12:00AM |
| Credit: | Vendor reported the issue. |
| Vulnerable: |
Cisco AnyConnect Secure Mobility Client 3.0 |
| Not Vulnerable: | |
Discussion
Cisco AnyConnect Secure Mobility Client CVE-2012-2498 Certificate Validation Vulnerability
Cisco AnyConnect Secure Mobility Client is prone to a security-bypass vulnerability.
Successfully exploiting these issues allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which may aid in further attacks.
Cisco AnyConnect Secure Mobility Client is prone to a security-bypass vulnerability.
Successfully exploiting these issues allows attackers to perform man-in-the-middle attacks or impersonate trusted servers, which may aid in further attacks.
Exploit / POC
Cisco AnyConnect Secure Mobility Client CVE-2012-2498 Certificate Validation Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco AnyConnect Secure Mobility Client CVE-2012-2498 Certificate Validation Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Cisco AnyConnect Secure Mobility Client CVE-2012-2498 Certificate Validation Vulnerability
References:
References:
- Cisco Homepage (Cisco )