Secure Desktop
Vendor:
First CVE: Oct 18, 2006 · Active for 19 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secure Desktop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2006
19 years ago
Most Recent CVE
Apr 17, 2015
4,116 days ago
CVE Severity & Scoring
Secure Desktop13 CVEs
23%
38%
38%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (7.7%)
Network0 (0.0%)
Unknown12 (92.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (7.7%)
High0 (0.0%)
Unknown12 (92.3%)
User Interaction
None1 (7.7%)
Unknown12 (92.3%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (92.3%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4655HIGH The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to exec | Sep 24, 2012 | 9.3 | 29 | NO | NO |
CVE-2011-0926HIGH A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote atta | Feb 25, 2011 | 9.3 | 29 | NO | NO |
CVE-2011-0925HIGH The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco program onto a client machine, | Feb 28, 2011 | 9.3 | 27 | NO | NO |
CVE-2010-0589HIGH The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote a | Apr 15, 2010 | 9.3 | 26 | NO | NO |
CVE-2015-0691HIGH A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CS | Apr 17, 2015 | 9.3 | 24 | NO | NO |
CVE-2010-0440MEDIUM Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2 | Feb 3, 2010 | 4.3 | 24 | NO | YES |
CVE-2012-2495MEDIUM The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offe | Jun 20, 2012 | 4.3 | 16 | NO | NO |
CVE-2006-5393MEDIUM Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pag | Oct 18, 2006 | 5.5 | 16 | NO | NO |
CVE-2006-5807MEDIUM Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka | Nov 8, 2006 | 4.6 | 14 | NO | NO |
CVE-2006-5808MEDIUM The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allo | Nov 8, 2006 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Secure Desktop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.6_base | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6249 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6234 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6228 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6210 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6203 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6104 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.6020 | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.6.5005 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6.4021 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6.3002 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6.2002 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6.185 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6.181 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6.1001 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.6 | 1 | 9.3 | 4.6% | 0 | 0 |
| 3.5_base | 1 | 9.3 | 3.1% | 0 | 0 |
| 3.5.841 | 3 | 7.6 | 3.0% | 0 | 0 |
| 3.5.2008 | 2 | 9.3 | 3.9% | 0 | 0 |
| 3.5.2003 | 1 | 9.3 | 3.1% | 0 | 0 |