Vulnerability CVE-2010-0589


Published: 2010-04-15   Modified: 2012-02-13

Description:
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> Secure desktop 

 References:
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtml
http://xforce.iss.net/xforce/xfdb/57812
http://www.zerodayinitiative.com/advisories/ZDI-10-072/
http://www.securityfocus.com/bid/39478
http://securitytracker.com/id?1023881

Copyright 2024, cxsecurity.com

 

Back to Top