9.3

CVE-2011-2040

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a Java applet, aka Bug ID CSCsy05934.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoAnyconnect Secure Mobility Client Version <= 2.5.2019
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.2.128
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.2.133
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.2.136
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.2.140
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.3.185
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.3.254
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.3.2016
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.4.0202
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.4.1012
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.1025
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2001
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2006
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2010
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2011
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2014
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2017
   ApplemacOS X
   LinuxLinux Kernel
CiscoAnyconnect Secure Mobility Client Version2.5.2018
   ApplemacOS X
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.09% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.