ID

VAR-201208-0707


CVE

CVE-2012-1370


TITLE

Cisco AnyConnect Secure Mobility Client Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2012-003443

DESCRIPTION

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670. Successful exploitation of the issue will cause the application to crash, resulting in a denial-of-service condition. This issue is being monitored by Cisco BugId CSCty01670

Trust: 1.98

sources: NVD: CVE-2012-1370 // JVNDB: JVNDB-2012-003443 // BID: 54841 // VULHUB: VHN-54651

AFFECTED PRODUCTS

vendor:ciscomodel:anyconnect secure mobility clientscope:eqversion:3.0

Trust: 1.9

vendor:ciscomodel:anyconnect secure mobility clientscope:eqversion:3.0.0629

Trust: 1.6

vendor:ciscomodel:anyconnect secure mobility clientscope:eqversion:3.0.07059

Trust: 1.6

vendor:ciscomodel:anyconnect secure mobility clientscope:ltversion:3.0

Trust: 0.8

vendor:ciscomodel:anyconnect secure mobility clientscope:eqversion:3.0.08057

Trust: 0.8

vendor:ciscomodel:anyconnect secure mobility clientscope:neversion:3.0.8057

Trust: 0.3

sources: BID: 54841 // JVNDB: JVNDB-2012-003443 // CNNVD: CNNVD-201208-004 // NVD: CVE-2012-1370

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1370
value: LOW

Trust: 1.0

NVD: CVE-2012-1370
value: LOW

Trust: 0.8

CNNVD: CNNVD-201208-004
value: LOW

Trust: 0.6

VULHUB: VHN-54651
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2012-1370
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-54651
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-54651 // JVNDB: JVNDB-2012-003443 // CNNVD: CNNVD-201208-004 // NVD: CVE-2012-1370

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-54651 // JVNDB: JVNDB-2012-003443 // NVD: CVE-2012-1370

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201208-004

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201208-004

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-003443

PATCH

title:Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.0url:http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect30/release/notes/anyconnect30rn.html

Trust: 0.8

sources: JVNDB: JVNDB-2012-003443

EXTERNAL IDS

db:NVDid:CVE-2012-1370

Trust: 2.8

db:JVNDBid:JVNDB-2012-003443

Trust: 0.8

db:CNNVDid:CNNVD-201208-004

Trust: 0.7

db:BIDid:54841

Trust: 0.4

db:VULHUBid:VHN-54651

Trust: 0.1

sources: VULHUB: VHN-54651 // BID: 54841 // JVNDB: JVNDB-2012-003443 // CNNVD: CNNVD-201208-004 // NVD: CVE-2012-1370

REFERENCES

url:http://www.cisco.com/en/us/docs/security/vpn_client/anyconnect/anyconnect30/release/notes/anyconnect30rn.html

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1370

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1370

Trust: 0.8

url:http://www.cisco.com/en/us/products/ps10884/index.html

Trust: 0.3

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-54651 // BID: 54841 // JVNDB: JVNDB-2012-003443 // CNNVD: CNNVD-201208-004 // NVD: CVE-2012-1370

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 54841

SOURCES

db:VULHUBid:VHN-54651
db:BIDid:54841
db:JVNDBid:JVNDB-2012-003443
db:CNNVDid:CNNVD-201208-004
db:NVDid:CVE-2012-1370

LAST UPDATE DATE

2025-04-11T23:19:34.276000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-54651date:2012-08-06T00:00:00
db:BIDid:54841date:2012-08-03T00:00:00
db:JVNDBid:JVNDB-2012-003443date:2012-08-07T00:00:00
db:CNNVDid:CNNVD-201208-004date:2012-08-08T00:00:00
db:NVDid:CVE-2012-1370date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-54651date:2012-08-06T00:00:00
db:BIDid:54841date:2012-08-03T00:00:00
db:JVNDBid:JVNDB-2012-003443date:2012-08-07T00:00:00
db:CNNVDid:CNNVD-201208-004date:2012-08-08T00:00:00
db:NVDid:CVE-2012-1370date:2012-08-06T15:55:01.290