CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 9.3. It affects Windows, Cisco, Linux and other products. It may be remotely exploitable.
CVE
CVE-2012-2493
Severity
HIGH
CVSS
9.3
EPSS
3.89%
Windows Cisco Linux Java
Original NVD Description
The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug ID CSCtw47523.