CVE-2021-1450
Cisco AnyConnect Secure Client vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2021-1450) was discovered in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client. The vulnerability was first published on February 24, 2021, and affects all releases earlier than 4.10.00093 of AnyConnect Secure Mobility Client for Windows, MacOS, and Linux platforms. The vulnerability does not affect AnyConnect Secure Mobility Client for Apple iOS, Android, and Universal Windows platforms (Cisco Advisory).

Technical details

The vulnerability stems from insufficient validation of user-supplied input in the IPC channel. It has been assigned a CVSS base score of 5.5 (Medium severity) with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X. The vulnerability is classified under CWE-20 (Cisco Advisory).

Impact

A successful exploitation of this vulnerability could allow an authenticated, local attacker to cause a denial of service (DoS) condition by stopping the AnyConnect process on an affected device. However, it's important to note that the affected process will automatically restart without requiring user or administrator intervention (Cisco Advisory).

Exploitability

The vulnerability requires local access and valid credentials on the target device for exploitation. An attacker could exploit this vulnerability by sending one or more crafted IPC messages to the AnyConnect process. The Cisco PSIRT has acknowledged the existence of proof-of-concept exploit code but is not aware of any malicious use of this vulnerability in the wild (Cisco Advisory).

Mitigation and workarounds

Cisco has released software updates to address this vulnerability in version 4.10.00093 and later releases of the AnyConnect Secure Mobility Client. No workarounds are available for this vulnerability. Customers are advised to upgrade to a fixed release and regularly consult Cisco Security Advisories for complete upgrade solutions (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco AnyConnect Secure Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20206HIGH7.8
  • Cisco AnyConnect Secure Client logoCisco AnyConnect Secure Client
  • cpe:2.3:a:cisco:secure_client
NoYesMar 05, 2025
CVE-2024-3661HIGH7.6
  • Rust logoRust
  • NetworkManager-cloud-setup
NoYesMay 06, 2024
CVE-2024-20391MEDIUM6.8
  • Cisco AnyConnect Secure Client logoCisco AnyConnect Secure Client
  • cpe:2.3:a:cisco:secure_client
NoYesMay 15, 2024
CVE-2024-20474MEDIUM6.5
  • Cisco AnyConnect Secure Client logoCisco AnyConnect Secure Client
  • cpe:2.3:a:cisco:anyconnect_secure_mobility_client
NoYesOct 23, 2024
CVE-2020-3432MEDIUM5.6
  • Cisco AnyConnect Secure Client logoCisco AnyConnect Secure Client
  • cpe:2.3:a:cisco:anyconnect_secure_mobility_client
NoYesFeb 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management