CVE-2012-3088
Cisco AnyConnect Secure Mobility Client <3.1.00495-3.2.x - RCE
Title source: llmDescription
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.
References (2)
Core 2
Core References
Release Notes x_refsource_confirm
http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/release/notes/anyconnect31rn.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78920
Scores
EPSS
0.0178
EPSS Percentile
76.0%
Details
Status
published
Products (2)
cisco/anyconnect_secure_mobility_client
3.1.0
cisco/anyconnect_secure_mobility_client
3.2.0
Published
Sep 16, 2012
Tracked Since
Feb 18, 2026