← Vulnerability feed

Vulnerability record · CVE-2024-20391 · published 15 May 2024

CVE-2024-20391: Cisco secure client missing authentication for critical function vulnerability

Cisco · Secure Client

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.

6.8 CVSS 3.1 Medium EPSS 0.35% · top 74.3% CWE-306 · Missing authentication for critical function
6.8CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20391 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2024-20337Cisco secure client vulnerabilityA vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage retur…EPSS 30%7.8CVE-2025-20206Cisco secure client improper verification of cryptographic signature vulnerabilityA vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to pe…EPSS 0.18%7.8CVE-2023-20178Cisco anyconnect secure mobility client incorrect default permissions vulnerabilityA vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Win…EPSS 5.4%7.6CVE-2024-3661Fortinet forticlient missing authentication for critical function vulnerabilityDHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi…EPSS 4.1%7.3CVE-2024-20338Cisco secure client uncontrolled search path element vulnerabilityA vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate priv…EPSS 0.89%6.5CVE-2024-20474Cisco anyconnect secure mobility client vulnerabilityA vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker…EPSS 0.60%5.5CVE-2023-20240Cisco anyconnect secure mobility client out-of-bounds read vulnerabilityMultiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to…EPSS 0.20%5.5CVE-2023-20241Cisco anyconnect secure mobility client out-of-bounds read vulnerabilityMultiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to…EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2024-20391), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.