VULNERABILITY INTELLIGENCE
CVE-2012-2499
CVSS score5.8 MEDIUM
EPSS probability0.53%
CISA KEVNot currently listed
Published2012-08-06
Last modified2026-06-16
Description
The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.