Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.
References
Configurations
History
21 Nov 2024, 01:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.infradead.org/openconnect.html - |
Information
Published : 2010-10-14 05:52
Updated : 2024-11-21 01:10
NVD link : CVE-2009-5008
Mitre link : CVE-2009-5008
CVE.ORG link : CVE-2009-5008
JSON object : View
Products Affected
cisco
- secure_desktop
CWE
CWE-264
Permissions, Privileges, and Access Controls