9.3
CVE-2012-3088
- EPSS 1.78%
- Veröffentlicht 16.09.2012 10:34:50
- Zuletzt bearbeitet 16.06.2026 23:42:34
- Erkennungen
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Anyconnect Secure Mobility Client Version 3.1.0
Cisco ≫ Anyconnect Secure Mobility Client Version 3.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.78% | 0.754 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect31/release/notes/anyconnect31rn.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/78920