CVE Vulnerabilities

CVE-2012-3088

Published: Sep 16, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.

Affected Software

Name Vendor Start Version End Version
Anyconnect_secure_mobility_client Cisco 3.1.0 (including) 3.1.0 (including)
Anyconnect_secure_mobility_client Cisco 3.2.0 (including) 3.2.0 (including)

References