Vulnerabilities > Cisco > Anyconnect Secure Mobility Client > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-28 CVE-2023-20178 Incorrect Default Permissions vulnerability in Cisco Anyconnect Secure Mobility Client and Secure Client
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM.
local
low complexity
cisco CWE-276
7.8
2021-11-04 CVE-2021-40124 Improper Privilege Management vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device.
local
low complexity
cisco CWE-269
7.8
2021-10-06 CVE-2021-34788 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client.
local
high complexity
cisco CWE-367
7.0
2021-05-06 CVE-2021-1426 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application.
local
low complexity
cisco CWE-427
7.8
2021-05-06 CVE-2021-1427 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application.
local
low complexity
cisco CWE-427
7.8
2021-05-06 CVE-2021-1428 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application.
local
low complexity
cisco CWE-427
7.8
2021-05-06 CVE-2021-1429 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application.
local
low complexity
cisco CWE-427
7.8
2021-05-06 CVE-2021-1430 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application.
local
low complexity
cisco CWE-427
7.8
2021-05-06 CVE-2021-1496 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application.
local
low complexity
cisco CWE-427
7.8
2021-02-17 CVE-2021-1366 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client.
local
low complexity
cisco CWE-427
7.8