Cisco Anyconnect Secure Mobility Client vulnerabilities
66 known vulnerabilities affecting cisco/anyconnect_secure_mobility_client.
Total CVEs
66
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM36LOW1
Vulnerabilities
Page 1 of 4
CVE-2020-3432MEDIUMCVSS 5.6fixed in 4.9.000862025-02-12
CVE-2020-3432 [MEDIUM] CWE-59 CVE-2020-3432: A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS c
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem.
The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a symbolic link (symlink) to
nvd
CVE-2024-20474MEDIUMCVSS 6.5v4.9.00086v4.9.01095+7 more2024-10-23
CVE-2024-20474 [MEDIUM] CWE-191 CVE-2024-20474: A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Softwar
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client.
This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to
nvd
CVE-2023-20240MEDIUMCVSS 5.5v4.9.00086v4.9.01095+7 more2023-11-22
CVE-2023-20240 [MEDIUM] CWE-125 CVE-2023-20240: Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnera
nvd
CVE-2023-20241MEDIUMCVSS 5.5v4.9.00086v4.9.01095+7 more2023-11-22
CVE-2023-20241 [MEDIUM] CWE-125 CVE-2023-20241: Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system.
These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnera
nvd
CVE-2023-20178HIGHCVSS 7.8fixed in 4.10.070612023-06-28
CVE-2023-20178 [HIGH] CWE-276 CVE-2023-20178: A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established.
This vuln
nvd
CVE-2021-40124HIGHCVSS 7.8fixed in 4.10.031042021-11-04
CVE-2021-40124 [MEDIUM] CWE-266 CVE-2021-40124: A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Clien
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user logon. An attacker could exploit this vulnerability by
nvd
CVE-2021-34788HIGHCVSS 7.0fixed in 4.10.031042021-10-06
CVE-2021-34788 [HIGH] CWE-367 CVE-2021-34788: A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client f
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition
nvd
CVE-2021-1567MEDIUMCVSS 6.7fixed in 4.10.010752021-06-16
CVE-2021-1567 [HIGH] CWE-367 CVE-2021-1567: A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows
A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition in the signature verification pro
nvd
CVE-2021-1568MEDIUMCVSS 5.5fixed in 4.10.010752021-06-16
CVE-2021-1568 [MEDIUM] CWE-789 CVE-2021-1568: A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated,
A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to a specific folder on the system. A
nvd
CVE-2021-1430HIGHCVSS 7.8fixed in 4.9.060372021-05-06
CVE-2021-1430 [HIGH] CWE-378 CVE-2021-1430: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2021-1426HIGHCVSS 7.8fixed in 4.9.060372021-05-06
CVE-2021-1426 [HIGH] CWE-378 CVE-2021-1426: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2021-1429HIGHCVSS 7.8fixed in 4.10.000932021-05-06
CVE-2021-1429 [HIGH] CWE-378 CVE-2021-1429: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2021-1427HIGHCVSS 7.8fixed in 4.9.060372021-05-06
CVE-2021-1427 [HIGH] CWE-378 CVE-2021-1427: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2021-1428HIGHCVSS 7.8fixed in 4.10.000932021-05-06
CVE-2021-1428 [HIGH] CWE-378 CVE-2021-1428: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2021-1496HIGHCVSS 7.8fixed in 4.9.030222021-05-06
CVE-2021-1496 [HIGH] CWE-378 CVE-2021-1496: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2021-1519MEDIUMCVSS 5.5fixed in 4.10.000932021-05-06
CVE-2021-1519 [MEDIUM] CWE-20 CVE-2021-1519: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted IPC
nvd
CVE-2021-1450MEDIUMCVSS 5.5v4.9\(5086\)2021-02-24
CVE-2021-1450 [MEDIUM] CWE-20 CVE-2021-1450: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The vulnerability is due to insufficien
nvd
CVE-2021-1366HIGHCVSS 7.8fixed in 4.9.050422021-02-17
CVE-2021-1366 [HIGH] CWE-347 CVE-2021-1366: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of reso
nvd
CVE-2021-1237HIGHCVSS 7.8fixed in 4.9.040432021-01-13
CVE-2021-1237 [HIGH] CWE-427 CVE-2021-1237: A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect
A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insuffici
nvd
CVE-2021-1258MEDIUMCVSS 5.5fixed in 4.9.03047fixed in 4.9.030492021-01-13
CVE-2021-1258 [MEDIUM] CWE-264 CVE-2021-1258: A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an a
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability b
nvd
1 / 4Next →