cbcvebase.

Cisco Anyconnect Secure Mobility Client vulnerabilities

66 known vulnerabilities affecting cisco/anyconnect_secure_mobility_client.

Total CVEs
66
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH26MEDIUM36LOW1

Vulnerabilities

Page 3 of 4
CVE-2020-3435P4MEDIUMCVSS 5.5≤ 4.9.000862020-08-17
CVE-2020-3435 [MEDIUM] CWE-20 CVE-2020-3435: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficie
nvd
CVE-2021-1519P4MEDIUMCVSS 5.5fixed in 4.10.000932021-05-06
CVE-2021-1519 [MEDIUM] CWE-20 CVE-2021-1519: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted IPC
nvd
CVE-2019-16007P4HIGHCVSS 7.1fixed in 4.8.008262020-09-23
CVE-2019-16007 [HIGH] CWE-345 CVE-2019-16007: A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for An A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service invocations. An attacker could exploit th
nvd
CVE-2015-0665P4MEDIUMCVSS 6.6≤ 4.0\(.00051\)2015-03-17
CVE-2015-0665 [MEDIUM] CWE-22 CVE-2015-0665: The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.
nvd
CVE-2015-6322P4MEDIUMCVSS 6.6v2.0.0343v2.1.0148+50 more2015-10-12
CVE-2015-6322 [MEDIUM] CWE-264 CVE-2015-6322: The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local user The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move arbitrary files by leveraging the lack of source-path validation, aka Bug ID CSCuv48563.
nvd
CVE-2015-0663P4MEDIUMCVSS 6.6≤ 4.0\(.00051\)2015-03-17
CVE-2015-0663 [MEDIUM] CWE-264 CVE-2015-0663: Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access c Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.
nvd
CVE-2020-3432P4MEDIUMCVSS 5.6fixed in 4.9.000862025-02-12
CVE-2020-3432 [MEDIUM] CWE-59 CVE-2020-3432: A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS c A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a symbolic link (symlink) to
nvd
CVE-2018-0334P4MEDIUMCVSS 4.8v4.6\(100\)2018-06-07
CVE-2018-0334 [MEDIUM] CWE-295 CVE-2018-0334: A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager a A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an unauthenticated, remote attacker to bypass the TLS certificate check when downloading certain configuration files. The vulnerability is due to im
nvd
CVE-2012-3094P4MEDIUMCVSS 5.0v3.1.02012-09-16
CVE-2012-3094 [MEDIUM] CWE-200 CVE-2012-3094: The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1. The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.
nvd
CVE-2015-0755P4MEDIUMCVSS 6.8v4.0\(64\)2015-05-29
CVE-2015-0755 [MEDIUM] CWE-284 CVE-2015-0755: The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secu The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797.
nvd
CVE-2013-1173P4MEDIUMCVSS 6.6v2.0v2.1+55 more2013-04-11
CVE-2013-1173 [MEDIUM] CWE-119 CVE-2013-1173: Heap-based buffer overflow in ciscod.exe in the Cisco Security Service in Cisco AnyConnect Secure Mo Heap-based buffer overflow in ciscod.exe in the Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14143.
nvd
CVE-2013-1172P4MEDIUMCVSS 6.6v2.0v2.1+55 more2013-04-11
CVE-2013-1172 [MEDIUM] CWE-20 CVE-2013-1172: The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) do The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153.
nvd
CVE-2012-2495P4MEDIUMCVSS 4.3v3.02012-06-20
CVE-2012-2495 [MEDIUM] CWE-20 CVE-2012-2495: The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed co
nvd
CVE-2012-2494P4MEDIUMCVSS 4.3v2.0v2.1+14 more2012-06-20
CVE-2012-2494 [MEDIUM] CWE-20 CVE-2012-2494: The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Clien The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attackers to force a version downgrade by using (1) ActiveX or (2) Java components to offer signed
nvd
CVE-2012-2499P4MEDIUMCVSS 5.8v3.0v3.0.0629+1 more2012-08-06
CVE-2012-2499 [MEDIUM] CWE-310 CVE-2012-2499: The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not ve The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz26985.
nvd
CVE-2023-20240P4MEDIUMCVSS 5.5v4.9.00086v4.9.01095+7 more2023-11-22
CVE-2023-20240 [MEDIUM] CWE-125 CVE-2023-20240: Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnera
nvd
CVE-2023-20241P4MEDIUMCVSS 5.5v4.9.00086v4.9.01095+7 more2023-11-22
CVE-2023-20241 [MEDIUM] CWE-125 CVE-2023-20241: Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An attacker could exploit these vulnera
nvd
CVE-2018-0373P4MEDIUMCVSS 5.5v4.5\(58\)v4.5\(1044\)+7 more2018-06-21
CVE-2018-0373 [MEDIUM] CWE-20 CVE-2018-0373: A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyC A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to improper validation of user-supplied data. An attacker could ex
nvd
CVE-2021-1450P4MEDIUMCVSS 5.5v4.9\(5086\)2021-02-24
CVE-2021-1450 [MEDIUM] CWE-20 CVE-2021-1450: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The vulnerability is due to insufficien
nvd
CVE-2021-1568P4MEDIUMCVSS 5.5fixed in 4.10.010752021-06-16
CVE-2021-1568 [MEDIUM] CWE-789 CVE-2021-1568: A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to a specific folder on the system. A
nvd
Cisco Anyconnect Secure Mobility Client vulnerabilities | cvebase