CVE-2009-5008: Low severity cisco secure vulnerability
Published Oct 12, 2010
·Updated
Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.
Affected Software
1 affected component
Cisco Secure Desktop
Event History
Oct 12, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-5008?
CVE-2009-5008 is classified as a high severity vulnerability.
2
How do I fix CVE-2009-5008?
To mitigate CVE-2009-5008, upgrade to the latest version of Cisco Secure Desktop that addresses this vulnerability.
3
What systems are affected by CVE-2009-5008?
CVE-2009-5008 affects Cisco Secure Desktop when used with AnyConnect SSL VPN servers.
4
Can CVE-2009-5008 be exploited remotely?
CVE-2009-5008 is primarily a local privilege escalation vulnerability.
5
What are the potential risks of CVE-2009-5008?
The risk of CVE-2009-5008 includes local users bypassing intended security policy restrictions.