📦 Anyconnect Secure Mobility Client

by Cisco

🔍 What is Anyconnect Secure Mobility Client?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-20178

HIGH CVSS 7.8 Jun 28, 2023

This vulnerability allows a low-privileged local attacker on Windows systems with Cisco AnyConnect or Secure Client to elevate privileges to SYSTEM level by exploiting improper permissions in the temp...

CVE-2021-34788

HIGH CVSS 7.0 Oct 6, 2021

This vulnerability allows authenticated local attackers to execute arbitrary code with root privileges on Linux and Mac OS systems running Cisco AnyConnect with the VPN Posture (HostScan) Module. Atta...

CVE-2021-1567

HIGH CVSS 7.0 Jun 16, 2021

This vulnerability allows an authenticated local attacker to perform DLL hijacking through a race condition in Cisco AnyConnect's signature verification process. Successful exploitation enables arbitr...

CVE-2021-1427

HIGH CVSS 7.0 May 6, 2021

This vulnerability in Cisco AnyConnect Secure Mobility Client for Windows allows authenticated local attackers to hijack DLL or executable files during install/uninstall/upgrade processes. Successful ...

CVE-2021-1429

HIGH CVSS 7.0 May 6, 2021

This vulnerability allows authenticated local attackers on Windows systems with Cisco AnyConnect Secure Mobility Client to hijack DLL or executable files during install/uninstall/upgrade processes. Su...

CVE-2021-1496

HIGH CVSS 7.0 May 6, 2021

This vulnerability allows authenticated local attackers on Windows systems with Cisco AnyConnect Secure Mobility Client to hijack DLL or executable files during installation/uninstallation/upgrade pro...

CVE-2020-3432

MEDIUM CVSS 5.6 Feb 12, 2025

This vulnerability in Cisco AnyConnect Secure Mobility Client for Mac OS allows authenticated local attackers to corrupt files via symlink attacks. Attackers need valid system credentials to exploit i...

CVE-2024-20474

MEDIUM CVSS 4.3 Oct 23, 2024

An integer underflow vulnerability in IKEv2 processing in Cisco Secure Client (formerly AnyConnect) allows unauthenticated remote attackers to crash the client via crafted packets, causing a denial of...