Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.
References
Link | Resource |
---|---|
http://www.infradead.org/openconnect.html |
Configurations
Information
Published : 2010-10-13 22:52
Updated : 2010-10-13 22:52
NVD link : CVE-2009-5008
Mitre link : CVE-2009-5008
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- secure_desktop