Secure Client

Vendor:

First CVE: Jun 28, 2023 · Active for 3 years

9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Secure Client over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2023
3 years ago
Most Recent CVE
Mar 5, 2025
506 days ago

CVE Severity & Scoring

Secure Client9 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local5 (55.6%)
Network2 (22.2%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network1 (11.1%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low5 (55.6%)
High0 (0.0%)
None4 (44.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection at
Mar 6, 20248.236NONO
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileg
Jun 28, 20237.828NONO
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to l
May 6, 20247.627NONO
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on
Mar 5, 20257.824NONO
A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device.
Mar 6, 20247.323NONO
A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate priv
May 15, 20246.820NONO
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (
Oct 23, 20246.518NONO
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS
Nov 22, 20235.518NONO
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS
Nov 22, 20235.517NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Secure Client

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.1.3.6216.50.6%00
5.1.2.4216.50.6%00
5.1.1.4216.50.6%00
5.1.0.13616.50.6%00
5.0.0504016.50.6%00
5.0.0403216.50.6%00
5.0.0307635.80.3%00
5.0.0307235.80.3%00
5.0.0207535.80.3%00
5.0.0124235.80.3%00
5.0.0055635.80.3%00
5.0.0052935.80.3%00
5.0.0023835.80.3%00
4.10.0802916.50.6%00
4.10.0802516.50.6%00
4.10.0707335.80.3%00
4.10.0706235.80.3%00
4.10.0706135.80.3%00
4.10.0609035.80.3%00
4.10.0607935.80.3%00