CVE Vulnerabilities

CVE-2012-3088

Published: Sep 16, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.

Affected Software

NameVendorStart VersionEnd Version
Anyconnect_secure_mobility_clientCisco3.1.0 (including)3.1.0 (including)
Anyconnect_secure_mobility_clientCisco3.2.0 (including)3.2.0 (including)

References