First published: Wed Oct 18 2006(Updated: )
Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Desktop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-5393 is considered moderate due to the potential for local users to access sensitive information from memory pages.
To fix CVE-2006-5393, ensure the ClearPageFileAtShutdown registry value is set to 1.
CVE-2006-5393 affects Cisco Secure Desktop.
CVE-2006-5393 enables attacks where local users can read sensitive data from another user's SSL VPN session.
A potential workaround for CVE-2006-5393 is to restrict access to the system for local users.