CVE detail
CVE-2012-2498 — CVE-2012-2498
Published 2012-08-06 · Modified 2026-06-16 · Vendor cisco · Product anyconnect_secure_mobility_client · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0048
EPSS probability
exploitation probability, 30d
39.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29197.
Remediation
| Product | Vulnerable range | Fixed version | Advisory |
|---|
| n/a n/a | — | not specified | advisory ↗ |
References