AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-2493

HIGH · CVSS 9.3 EPSS 3.89%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-06-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 9.3. It affects Windows, Cisco, Linux and other products. It may be remotely exploitable.

CVE
CVE-2012-2493
Severity
HIGH
CVSS
9.3
EPSS
3.89%
Windows Cisco Linux Java

Original NVD Description

The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2.5 MR6 and 3.x before 3.0 MR8 on Mac OS X and Linux, does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka Bug ID CSCtw47523.