CVE-2025-20206
- EPSS 0.01%
- Published 05.03.2025 17:15:14
- Last modified 22.07.2025 18:04:12
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly Ho...
CVE-2020-3432
- EPSS 0.05%
- Published 12.02.2025 00:15:07
- Last modified 24.06.2025 00:12:09
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling ...
CVE-2024-20474
- EPSS 0.1%
- Published 23.10.2024 18:15:11
- Last modified 01.11.2024 18:14:56
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an intege...
CVE-2024-20391
- EPSS 0.27%
- Published 15.05.2024 18:15:10
- Last modified 22.07.2025 18:02:45
A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentica...
CVE-2024-3661
- EPSS 2.67%
- Published 06.05.2024 19:15:11
- Last modified 15.01.2025 16:50:28
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local...
CVE-2024-20337
- EPSS 6.58%
- Published 06.03.2024 17:15:09
- Last modified 22.07.2025 18:00:37
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient val...
CVE-2024-20338
- EPSS 0.11%
- Published 06.03.2024 17:15:09
- Last modified 22.07.2025 18:04:59
A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path ...
CVE-2023-20240
- EPSS 0.03%
- Published 22.11.2023 17:15:18
- Last modified 21.11.2024 07:40:58
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an...
CVE-2023-20241
- EPSS 0.03%
- Published 22.11.2023 17:15:18
- Last modified 21.11.2024 07:40:58
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to...
CVE-2023-20178
- EPSS 27.05%
- Published 28.06.2023 15:15:09
- Last modified 21.11.2024 07:40:45
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SY...