VYPR

Secure Client

by Cisco Systems, Inc.

CVEs (9)

  • CVE-2024-20337HigMar 6, 2024
    risk 0.56cvss 8.2epss 0.30

    A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user-supplied…

  • CVE-2023-20178HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.05

    A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update…

  • CVE-2024-20338HigMar 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. An attacker could…

  • CVE-2025-20206HigMar 5, 2025
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is installed on Cisco…

  • CVE-2024-20391MedMay 15, 2024
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function.…

  • CVE-2020-3432MedFeb 12, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An…

  • CVE-2023-20241MedNov 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read…

  • CVE-2023-20240MedNov 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read…

  • CVE-2024-20474MedOct 23, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An…