Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.
References
Configurations
History
No history.
Information
Published : 2010-10-14 05:52
Updated : 2025-04-11 00:51
NVD link : CVE-2009-5008
Mitre link : CVE-2009-5008
CVE.ORG link : CVE-2009-5008
JSON object : View
Products Affected
cisco
- secure_desktop
CWE
CWE-264
Permissions, Privileges, and Access Controls