Executive Summary

Summary
Title Cisco Secure Desktop ActiveX Control Code Execution Vulnerability
Informations
Name cisco-sa-20100414-csd First vendor Publication 2010-02-08
Vendor Cisco Last vendor Modification 2012-02-01
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cisco Secure Desktop contains a vulnerable ActiveX control that could allow an attacker to execute arbitrary code with the privileges of the user who is currently logged into the affected system. Cisco has released a free software update that addresses this vulnerability. There is a workaround that mitigates this vulnerability.

Original Source

Url : http://www.cisco.com/warp/public/707/cisco-sa-20100414-csd.shtml

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-20 Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 28

Open Source Vulnerability Database (OSVDB)

Id Description
63809 Cisco Secure Desktop (CSD) CSDWebInstaller ActiveX Signature Verification Arb...