CVE-2010-0589

The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:secure_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.1.1.27:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.1.1.33:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_desktop:3.4.2048:*:*:*:*:*:*:*

History

21 Nov 2024, 01:12

Type Values Removed Values Added
References () http://securitytracker.com/id?1023881 - () http://securitytracker.com/id?1023881 -
References () http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtml - Patch, Vendor Advisory () http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtml - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/39478 - () http://www.securityfocus.com/bid/39478 -
References () http://www.zerodayinitiative.com/advisories/ZDI-10-072/ - () http://www.zerodayinitiative.com/advisories/ZDI-10-072/ -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/57812 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/57812 -

Information

Published : 2010-04-15 17:30

Updated : 2024-11-21 01:12


NVD link : CVE-2010-0589

Mitre link : CVE-2010-0589

CVE.ORG link : CVE-2010-0589


JSON object : View

Products Affected

cisco

  • secure_desktop
CWE
CWE-20

Improper Input Validation