Cisco
Cisco Anyconnect Secure Mobility Client: vulnerabilidades y CVE
Cisco Anyconnect Secure Mobility Client tiene 69 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE69
Últimos 12 meses0
Críticas0
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-3153 | Media (6.5) | 28% | ⚠ Explotación activa | 19 feb 2020 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level… |
| CVE-2020-3433 | Alta (7.8) | 10% | ⚠ Explotación activa | 17 ago 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-3432 | Media (5.6) | 0.23% | — | 12 feb 2025 | A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is… |
| CVE-2024-20474 | Media (6.5) | 0.60% | — | 23 oct 2024 | A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This… |
| CVE-2023-20241 | Media (5.5) | 0.20% | — | 22 nov 2023 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system.… |
| CVE-2023-20240 | Media (5.5) | 0.20% | — | 22 nov 2023 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system.… |
| CVE-2023-20178 | Alta (7.8) | 5.4% | — | 28 jun 2023 | A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to… |
| CVE-2021-40124 | Alta (7.8) | 0.24% | — | 4 nov 2021 | A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This… |
| CVE-2021-34788 | Alta (7) | 0.18% | — | 6 oct 2021 | A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an… |
| CVE-2021-1568 | Media (5.5) | 0.21% | — | 16 jun 2021 | A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to… |
| CVE-2021-1567 | Media (6.7) | 0.18% | — | 16 jun 2021 | A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture… |
| CVE-2021-1519 | Media (5.5) | 0.21% | — | 6 may 2021 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. The… |
| CVE-2021-1496 | Alta (7.8) | 0.53% | — | 6 may 2021 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are… |
| CVE-2021-1430 | Alta (7.8) | 0.23% | — | 6 may 2021 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are… |
| CVE-2021-1429 | Alta (7.8) | 0.25% | — | 6 may 2021 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are… |
| CVE-2021-1428 | Alta (7.8) | 0.25% | — | 6 may 2021 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are… |
| CVE-2021-1427 | Alta (7.8) | 0.25% | — | 6 may 2021 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are… |
| CVE-2021-1426 | Alta (7.8) | 0.25% | — | 6 may 2021 | Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are… |
| CVE-2021-1450 | Media (5.5) | 0.23% | — | 24 feb 2021 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.… |
| CVE-2021-1366 | Alta (7.8) | 1.3% | — | 17 feb 2021 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device… |
| CVE-2021-1258 | Media (5.5) | 0.34% | — | 13 ene 2021 | A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an… |
| CVE-2021-1237 | Alta (7.8) | 0.40% | — | 13 ene 2021 | A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To… |
| CVE-2020-3556 | Alta (7.3) | 0.45% | — | 6 nov 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious… |
| CVE-2020-27123 | Media (5.5) | 0.33% | — | 6 nov 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating… |
| CVE-2019-16007 | Alta (7.1) | 0.36% | — | 23 sept 2020 | A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause… |
| CVE-2020-3435 | Media (5.5) | 0.34% | — | 17 ago 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. To… |
| CVE-2020-3434 | Media (5.5) | 0.46% | — | 17 ago 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an… |
| CVE-2020-3433 | Alta (7.8) | 10% | ⚠ Explotación activa | 17 ago 2020 | A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this… |
| CVE-2020-3153 | Media (6.5) | 28% | ⚠ Explotación activa | 19 feb 2020 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level… |
| CVE-2019-1853 | Alta (7.5) | 1.6% | — | 16 may 2019 | A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability… |
| CVE-2018-0373 | Media (5.5) | 0.39% | — | 21 jun 2018 | A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of… |
| CVE-2018-0334 | Media (4.8) | 0.98% | — | 7 jun 2018 | A vulnerability in the certificate management subsystem of Cisco AnyConnect Network Access Manager and of Cisco AnyConnect Secure Mobility Client for iOS, Mac OS X, Android, Windows, and Linux could allow an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.