Cisco-SA-20120620-CVE-2012-2494
Cisco AnyConnect Secure Mobility Client Software Downgrade Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
Cisco AnyConnect Secure Mobility Client contains a vulnerability that could allow an unauthenticated, remote attacker to replace software components. The vulnerability is due to improper sanitization of user-supplied input by the affected software's download feature. An unauthenticated, remote attacker could exploit this vulnerability by persuading a user to view a malicious website. If successful, the attacker could cause the affected software to download and install an older version of the software. Cisco has confirmed the vulnerability in a security advisory and released software updates. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
| Product | CVE |
|---|---|
| Cisco AnyConnect Secure Mobility Client | CVE-2012-2494 |