Lucene search

K
ciscoCiscoCISCO-SA-20150415-CSD
HistoryApr 15, 2015 - 4:00 p.m.

Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability

2015-04-1516:00:00
tools.cisco.com
15

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

59.8%

A vulnerability in a Cisco-signed Java Archive (JAR)
executable Cache Cleaner component of Cisco Secure Desktop could allow an
unauthenticated, remote attacker to execute arbitrary commands on the
client host where the affected .jar file is executed. Command execution would
occur with the privileges of the user.

The Cache Cleaner feature has been deprecated since November 2012.

There is no fixed software for this vulnerability. Cisco Secure Desktop packages that include the affected .jar files have been removed and are no longer available for download.

Because Cisco does not control all existing Cisco Secure Desktop packages, customers are advised to ensure that their Java blacklist controls have been updated to avoid potential exploitation. Refer to the “Workarounds” section of this advisory for additional information on how to mitigate this vulnerability.

Customers using Cisco Secure Desktop should migrate to the Cisco Host Scan standalone package.

This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150415-csd[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150415-csd”]

Affected configurations

Vulners
Node
ciscosecure_desktopMatchany
OR
ciscosecure_desktopMatchany
VendorProductVersionCPE
ciscosecure_desktopanycpe:2.3:a:cisco:secure_desktop:any:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

59.8%

Related for CISCO-SA-20150415-CSD