Lucene search

K
nvd[email protected]NVD:CVE-2011-2039
HistoryJun 02, 2011 - 7:55 p.m.

CVE-2011-2039

2011-06-0219:55:04
CWE-20
web.nvd.nist.gov
5

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.807

Percentile

98.4%

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.

Affected configurations

Nvd
Node
ciscoanyconnect_secure_mobility_clientRange≀2.3
OR
ciscoanyconnect_secure_mobility_clientMatch2.0
OR
ciscoanyconnect_secure_mobility_clientMatch2.1
OR
ciscoanyconnect_secure_mobility_clientMatch2.2
OR
ciscoanyconnect_secure_mobility_clientMatch2.2.128
OR
ciscoanyconnect_secure_mobility_clientMatch2.2.133
OR
ciscoanyconnect_secure_mobility_clientMatch2.2.136
OR
ciscoanyconnect_secure_mobility_clientMatch2.2.140
AND
microsoftwindows
OR
microsoftwindows_mobile
VendorProductVersionCPE
ciscoanyconnect_secure_mobility_client*cpe:2.3:a:cisco:anyconnect_secure_mobility_client:*:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.0cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.0:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.1cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.1:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.2cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.2.128cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.128:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.2.133cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.133:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.2.136cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.136:*:*:*:*:*:*:*
ciscoanyconnect_secure_mobility_client2.2.140cpe:2.3:a:cisco:anyconnect_secure_mobility_client:2.2.140:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
microsoftwindows_mobile*cpe:2.3:o:microsoft:windows_mobile:*:*:*:*:*:*:*:*

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.807

Percentile

98.4%