CVE-2014-3314: Cisco AnyConnect Secure Mobility Client

Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 and CSCuo24940.

Affected products

  • Cisco AnyConnect Secure Mobility Client: any version

Published 2015-01-14. Last modified 2026-06-17.