CVE-2006-5394: Low severity Cisco Secure Desktop vulnerability
The default configuration of Cisco Secure Desktop (CSD) has an unchecked "Disable printing" box in Secure Desktop Settings, which might allow local users to read data that was sent to a printer during another user's SSL VPN session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5394?
CVE-2006-5394 is considered to have moderate severity due to potential information disclosure.
How do I fix CVE-2006-5394?
To mitigate CVE-2006-5394, ensure that the 'Disable printing' option in Secure Desktop Settings is properly configured.
Which versions of Cisco Secure Desktop are affected by CVE-2006-5394?
CVE-2006-5394 affects all versions of Cisco Secure Desktop with the default configuration.
What kind of data can be accessed due to CVE-2006-5394?
CVE-2006-5394 may allow local users to read sensitive data that was sent to a printer during another user's SSL VPN session.
Is there a workaround for CVE-2006-5394?
A potential workaround for CVE-2006-5394 is to change the settings in Cisco Secure Desktop to restrict printing options.