cbcvebase.

Cisco Anyconnect Secure Mobility Client vulnerabilities

66 known vulnerabilities affecting cisco/anyconnect_secure_mobility_client.

Total CVEs
66
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM36LOW1

Vulnerabilities

Page 2 of 4
CVE-2021-40124P3HIGHCVSS 7.8fixed in 4.10.031042021-11-04
CVE-2021-40124 [HIGH] CWE-266 CVE-2021-40124: A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Clien A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user logon. An attacker could exploit this vulnerability by c
nvd
CVE-2021-1430P3HIGHCVSS 7.8fixed in 4.9.060372021-05-06
CVE-2021-1430 [HIGH] CWE-378 CVE-2021-1430: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
nvd
CVE-2012-3088P3CRITICALCVSS 9.3v3.1.0v3.2.02012-09-16
CVE-2012-3088 [CRITICAL] CVE-2012-3088: Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.
nvd
CVE-2017-6638P3HIGHCVSS 7.8≤ 4.4.002432017-06-08
CVE-2017-6638 [HIGH] CWE-264 CVE-2017-6638: A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYSTEM account. The vulnerability is due to incomplete input validation of path and file names of a DLL file before it
nvd
CVE-2018-0229P3MEDIUMCVSS 6.5v4.6\(200\)2018-04-19
CVE-2018-0229 [MEDIUM] CWE-384 CVE-2018-0229: A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (S A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish an aut
nvd
CVE-2015-4289P3MEDIUMCVSS 6.4v4.0\(2049\)2015-08-01
CVE-2015-4289 [MEDIUM] CWE-22 CVE-2015-4289: Directory traversal vulnerability in Cisco AnyConnect Secure Mobility Client 4.0(2049) allows remote Directory traversal vulnerability in Cisco AnyConnect Secure Mobility Client 4.0(2049) allows remote head-end systems to write to arbitrary files via a crafted configuration attribute, aka Bug ID CSCut93920.
nvd
CVE-2016-6369P3HIGHCVSS 7.8v2.0.0343v2.1.0148+55 more2016-08-25
CVE-2016-6369 [HIGH] CWE-264 CVE-2016-6369: Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathn Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.
nvd
CVE-2021-34788P3HIGHCVSS 7.0fixed in 4.10.031042021-10-06
CVE-2021-34788 [HIGH] CWE-367 CVE-2021-34788: A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client f A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition
nvd
CVE-2020-3556P3HIGHCVSS 7.3v4.9\(3052\)v98.145\(86\)2020-11-06
CVE-2020-3556 [HIGH] CWE-20 CVE-2020-3556: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could exploit this vulnerability by sending
nvd
CVE-2012-2496P3MEDIUMCVSS 6.8v3.02012-06-20
CVE-2012-2496 [MEDIUM] CWE-20 CVE-2012-2496: A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConn A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on 64-bit Linux platforms does not properly restrict use of Java components, which allows remote attackers to execute arbitrary code via a crafted web site, aka Bug ID CSCty45925.
nvd
CVE-2013-5559P3MEDIUMCVSS 6.8v2.0v2.1+40 more2013-11-04
CVE-2013-5559 [MEDIUM] CWE-119 CVE-2013-5559: Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco Any Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.
nvd
CVE-2021-1567P4MEDIUMCVSS 6.7fixed in 4.10.010752021-06-16
CVE-2021-1567 [MEDIUM] CWE-367 CVE-2021-1567: A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition in the signature verification p
nvd
CVE-2024-20474P4MEDIUMCVSS 6.5v4.9.00086v4.9.01095+7 more2024-10-23
CVE-2024-20474 [MEDIUM] CWE-191 CVE-2024-20474: A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Softwar A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to
nvd
CVE-2015-0662P4HIGHCVSS 7.2≤ 4.0\(.00051\)2015-03-17
CVE-2015-0662 [HIGH] CWE-264 CVE-2015-0662: Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privilege Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of root privileges for a software-package installation, aka Bug ID CSCus79385.
nvd
CVE-2021-1258P4MEDIUMCVSS 5.5fixed in 4.9.03047fixed in 4.9.030492021-01-13
CVE-2021-1258 [MEDIUM] CWE-264 CVE-2021-1258: A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an a A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability b
nvd
CVE-2020-27123P4MEDIUMCVSS 5.5fixed in 4.9.030472020-11-06
CVE-2020-27123 [MEDIUM] CWE-749 CVE-2020-27123: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could exploit this vulnerability by sendi
nvd
CVE-2017-6788P4MEDIUMCVSS 6.1v4.4\(4027\)v4.5\(58\)2017-08-17
CVE-2017-6788 [MEDIUM] CWE-79 CVE-2017-6788: The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerabi The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the WebLaunc
nvd
CVE-2017-12268P4MEDIUMCVSS 6.5v4.5\(822\)2017-10-05
CVE-2017-12268 [MEDIUM] CWE-264 CVE-2017-12268: A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insufficient NAM policy enforcement. An attacker could exploit this vulnerability by manipulating networ
nvd
CVE-2015-0761P4HIGHCVSS 7.2≤ 3.1\(.07021\)v4.0\(.00048\)+1 more2015-06-04
CVE-2015-0761 [HIGH] CWE-264 CVE-2015-0761: Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions, which allows local users to obtain root privileges via crafted vpnagent options, aka Bug ID CSCus86790.
nvd
CVE-2011-2041P4HIGHCVSS 7.2≤ 2.3.2016v2.0+8 more2011-06-02
CVE-2011-2041 [HIGH] CWE-264 CVE-2011-2041: The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyC The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and on Windows Mobile, allows local users to gain privileges via unspecified user-interface interaction, aka Bug ID CSCta40556.
nvd
Cisco Anyconnect Secure Mobility Client vulnerabilities | cvebase