CVE-2012-3088
Last modified
CVE-2012-3088 is a vulnerability of currently unknown severity. Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.. EPSS estimates a 1.78% chance of exploitation in the next 30 days.
Description
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Anyconnect Secure Mobility Client | 3.1.0 |
| Cisco | Anyconnect Secure Mobility Client | 3.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3088?
How severe is CVE-2012-3088?
How do I fix CVE-2012-3088?
Are you affected by CVE-2012-3088?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
