Lucene search

K
cveMitreCVE-2006-5808
HistoryNov 08, 2006 - 10:07 p.m.

CVE-2006-5808

2006-11-0822:07:00
mitre
web.nvd.nist.gov
25
cisco
secure
desktop
csd
insecure default permissions
local privilege escalation
cve-2006-5808
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

25.6%

The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka “Local Privilege Escalation”.

Affected configurations

Nvd
Node
ciscosecure_desktopRange3.1.1.33
OR
ciscosecure_desktopMatch3.1.1.27
VendorProductVersionCPE
ciscosecure_desktop*cpe:2.3:a:cisco:secure_desktop:*:*:*:*:*:*:*:*
ciscosecure_desktop3.1.1.27cpe:2.3:a:cisco:secure_desktop:3.1.1.27:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

25.6%

Related for CVE-2006-5808