CVE-2024-20474: Cisco AnyConnect Secure Mobility Client

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by sending a crafted IKEv2 packet to an affected system. A successful exploit could allow the attacker to cause Cisco Secure Client Software to crash, resulting in a DoS condition on the client software. Note: Cisco Secure Client Software releases 4.10 and earlier were known as Cisco AnyConnect Secure Mobility Client.

Affected products

  • Cisco AnyConnect Secure Mobility Client: version 4.9.00086 only; version 4.9.01095 only; version 4.9.02028 only; version 4.9.03047 only; version 4.9.03049 only; version 4.9.04043 only; …
  • Cisco Secure Client: version 4.10.00093 only; version 4.10.01075 only; version 4.10.02086 only; version 4.10.03104 only; version 4.10.04065 only; version 4.10.04071 only; …

Published 2024-10-23. Last modified 2026-06-17.