CVE-2019-16007: Cisco AnyConnect Secure Mobility Client

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service invocations. An attacker could exploit this vulnerability by persuading a user to install a malicious application. A successful exploit could allow the attacker to access confidential user information or cause a DoS condition on the AnyConnect application.

Affected products

  • Cisco AnyConnect Secure Mobility Client: before 4.8.00826 (fixed in 4.8.00826)

Published 2020-09-23. Last modified 2026-06-17.