Vulnslist

find the latest Cisco vulnerabilities

CVE-2012-2498

Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.

SeverityMEDIUM
CVSS4.0
CWECWE-287
KEV
Published
Modified

Related Products

Product Advisory
Cisco Secure Client Cisco-SA-20120809-CVE-2012-2498
Cisco AnyConnect Secure Mobility Client Cisco-SA-20120809-CVE-2012-2498