CVE-2024-3661: Cisco AnyConnect VPN Client

High severity, CVSS 7.6. EPSS: 4.1% chance of exploitation in the next 30 days.

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Affected products

  • Cisco AnyConnect VPN Client: affected versions not specified
  • Cisco Secure Client: affected versions not specified
  • Citrix Secure Access Client: before 24.06.1 (fixed in 24.06.1); before 24.8.5 (fixed in 24.8.5)
  • F5 BIG-IP Access Policy Manager: from 7.2.3, up to and including 7.2.5; from 15.1.0, up to and including 15.1.10; from 16.1.0, up to and including 16.1.5; from 17.1.0, up to and including 17.1.2
  • Fortinet FortiClient: from 6.4.0, before 7.2.5 (fixed in 7.2.5); version 7.4.0 only
  • Palo Alto Networks Globalprotect: any version
  • WatchGuard Ipsec Mobile VPN Client: any version
  • WatchGuard Mobile VPN With SSL: any version
  • Zscaler Client Connector: before 1.5.1.25 (fixed in 1.5.1.25); before 4.2.0.282 (fixed in 4.2.0.282); from 3.7, before 3.7.0.134 (fixed in 3.7.0.134); affected versions not specified

Published 2024-05-06. Last modified 2026-06-17.