Secure Desktop

Vendor:

First CVE: Oct 18, 2006 · Active for 19 years

13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Secure Desktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2006
19 years ago
Most Recent CVE
Apr 17, 2015
4,116 days ago

CVE Severity & Scoring

Secure Desktop13 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local1 (7.7%)
Network0 (0.0%)
Unknown12 (92.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (7.7%)
High0 (0.0%)
Unknown12 (92.3%)
User Interaction
None1 (7.7%)
Unknown12 (92.3%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (92.3%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to exec
Sep 24, 20129.329NONO
A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote atta
Feb 25, 20119.329NONO
The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco program onto a client machine,
Feb 28, 20119.327NONO
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote a
Apr 15, 20109.326NONO
A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CS
Apr 17, 20159.324NONO
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2
Feb 3, 20104.324NOYES
The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offe
Jun 20, 20124.316NONO
Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pag
Oct 18, 20065.516NONO
Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka
Nov 8, 20064.614NONO
The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allo
Nov 8, 20064.614NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Secure Desktop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.6_base19.33.1%00
3.6.624919.33.1%00
3.6.623419.33.1%00
3.6.622819.33.1%00
3.6.621019.33.1%00
3.6.620319.33.1%00
3.6.610419.33.1%00
3.6.602019.33.1%00
3.6.500529.33.9%00
3.6.402129.33.9%00
3.6.300229.33.9%00
3.6.200229.33.9%00
3.6.18529.33.9%00
3.6.18129.33.9%00
3.6.100129.33.9%00
3.619.34.6%00
3.5_base19.33.1%00
3.5.84137.63.0%00
3.5.200829.33.9%00
3.5.200319.33.1%00