Cisco Anyconnect Secure Mobility Client vulnerabilities

23 known vulnerabilities affecting cisco/cisco_anyconnect_secure_mobility_client.

Total CVEs
23
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
HIGH14MEDIUM9

Vulnerabilities

Page 1 of 2
CVE-2021-40124HIGHCVSS 7.8vn/a2021-11-04
CVE-2021-40124 [MEDIUM] CWE-266 CVE-2021-40124: A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Clien A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user logon. An attacker could exploit this vulnerability by
cvelistv5nvd
CVE-2021-34788HIGHCVSS 7.0vn/a2021-10-06
CVE-2021-34788 [HIGH] CWE-367 CVE-2021-34788: A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client f A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition
cvelistv5nvd
CVE-2021-1567MEDIUMCVSS 6.7vn/a2021-06-16
CVE-2021-1567 [HIGH] CWE-367 CVE-2021-1567: A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race condition in the signature verification pro
cvelistv5nvd
CVE-2021-1568MEDIUMCVSS 5.5vn/a2021-06-16
CVE-2021-1568 [MEDIUM] CWE-789 CVE-2021-1568: A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to a specific folder on the system. A
cvelistv5nvd
CVE-2021-1427HIGHCVSS 7.8vn/a2021-05-06
CVE-2021-1427 [HIGH] CWE-378 CVE-2021-1427: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
cvelistv5nvd
CVE-2021-1430HIGHCVSS 7.8vn/a2021-05-06
CVE-2021-1430 [HIGH] CWE-378 CVE-2021-1430: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
cvelistv5nvd
CVE-2021-1426HIGHCVSS 7.8vn/a2021-05-06
CVE-2021-1426 [HIGH] CWE-378 CVE-2021-1426: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
cvelistv5nvd
CVE-2021-1429HIGHCVSS 7.8vn/a2021-05-06
CVE-2021-1429 [HIGH] CWE-378 CVE-2021-1429: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
cvelistv5nvd
CVE-2021-1496HIGHCVSS 7.8vn/a2021-05-06
CVE-2021-1496 [HIGH] CWE-378 CVE-2021-1496: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
cvelistv5nvd
CVE-2021-1428HIGHCVSS 7.8vn/a2021-05-06
CVE-2021-1428 [HIGH] CWE-378 CVE-2021-1428: Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privile
cvelistv5nvd
CVE-2021-1519MEDIUMCVSS 5.5vn/a2021-05-06
CVE-2021-1519 [MEDIUM] CWE-20 CVE-2021-1519: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted IPC
cvelistv5nvd
CVE-2021-1450MEDIUMCVSS 5.5vn/a2021-02-24
CVE-2021-1450 [MEDIUM] CWE-20 CVE-2021-1450: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The vulnerability is due to insufficien
cvelistv5nvd
CVE-2021-1366HIGHCVSS 7.8vn/a2021-02-17
CVE-2021-1366 [HIGH] CWE-347 CVE-2021-1366: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of reso
cvelistv5nvd
CVE-2021-1237HIGHCVSS 7.8vn/a2021-01-13
CVE-2021-1237 [HIGH] CWE-427 CVE-2021-1237: A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insuffici
cvelistv5nvd
CVE-2021-1258MEDIUMCVSS 5.5vn/a2021-01-13
CVE-2021-1258 [MEDIUM] CWE-264 CVE-2021-1258: A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an a A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability b
cvelistv5nvd
CVE-2020-3556HIGHCVSS 7.3vn/a2020-11-06
CVE-2020-3556 [HIGH] CWE-20 CVE-2020-3556: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could exploit this vulnerability by sending
cvelistv5nvd
CVE-2020-27123MEDIUMCVSS 5.5vn/a2020-11-06
CVE-2020-27123 [MEDIUM] CWE-749 CVE-2020-27123: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could exploit this vulnerability by sendi
cvelistv5nvd
CVE-2019-16007HIGHCVSS 7.1vn/a2020-09-23
CVE-2019-16007 [HIGH] CWE-345 CVE-2019-16007: A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for An A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service invocations. An attacker could exploit th
cvelistv5nvd
CVE-2020-3433HIGHCVSS 7.8KEVPoCvn/a2020-08-17
CVE-2020-3433 [HIGH] CWE-427 CVE-2020-3433: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation o
cvelistv5nvd
CVE-2020-3434MEDIUMCVSS 5.5vn/a2020-08-17
CVE-2020-3434 [MEDIUM] CWE-20 CVE-2020-3434: A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability i
cvelistv5nvd