Very Pwnable Network: Cisco AnyConnect Security Analysis
Gerbert Roitburd, Matthias Ortmann, Matthias Hollick, Jiska Classen

TL;DR
This paper analyzes the security of Cisco AnyConnect VPN clients across Linux and iOS, revealing 13 new vulnerabilities and highlighting architecture-specific security issues and their implications for enterprise network safety.
Contribution
It provides the first comprehensive security analysis of Cisco AnyConnect on Linux and iOS, uncovering new vulnerabilities through reverse engineering and fuzzing.
Findings
13 new vulnerabilities discovered in Cisco AnyConnect
Linux client has deep-rooted privilege escalation issues
iOS analysis reveals specific and general VPN security bugs
Abstract
Corporate Virtual Private Networks (VPNs) enable users to work from home or while traveling. At the same time, VPNs are tied to a company's network infrastructure, forcing users to install proprietary clients for network compatibility reasons. VPN clients run with high privileges to encrypt and reroute network traffic. Thus, bugs in VPN clients pose a substantial risk to their users and in turn the corporate network. Cisco, the dominating vendor of enterprise network hardware, offers VPN connectivity with their AnyConnect client for desktop and mobile devices. While past security research primarily focused on the AnyConnect Windows client, we show that Linux and iOS are based on different architectures and have distinct security issues. Our reverse engineering as well as the follow-up design analysis and fuzzing reveal 13 new vulnerabilities. Seven of these are located in the Linux…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · IPv6, Mobility, Handover, Networks, Security · Cloud Computing and Remote Desktop Technologies
