CVE-2011-2040: Input Validation
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a Java applet, aka Bug ID CSCsy05934.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2040?
CVE-2011-2040 has a medium severity rating due to the lack of authenticity verification when downloading client executables.
How do I fix CVE-2011-2040?
To fix CVE-2011-2040, upgrade to Cisco AnyConnect Secure Mobility Client version 2.5.3041 or later, or 3.0.629 or later.
What systems are affected by CVE-2011-2040?
CVE-2011-2040 affects versions of Cisco AnyConnect Secure Mobility Client prior to 2.5.3041 and 3.0.x before 3.0.629 on Linux and Mac OS X.
Can CVE-2011-2040 allow remote code execution?
Yes, CVE-2011-2040 can allow remote attackers to execute arbitrary code on affected systems.
Is there a workaround for CVE-2011-2040?
There is no documented workaround for CVE-2011-2040, and the recommended action is to update to a patched version.