SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when...
Vulnerability Description
SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files outside of the vault, which is not cleared after the VPN connection terminates and allows local users to read unencrypted data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-5806
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securitytracker.com/id?1017195
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30129
- http://secunia.com/advisories/22747
- http://www.osvdb.org/30306
- http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml
- http://www.vupen.com/english/advisories/2006/4409
- http://www.securityfocus.com/bid/20964
More from cisco
View All →Affected Vendor
cisco
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.