Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-0691


A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001.


Published

2015-04-17T01:59:25.420

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco secure_desktop 3.0_base Yes
Application cisco secure_desktop 3.1.0.31 Yes
Application cisco secure_desktop 3.1.1 Yes
Application cisco secure_desktop 3.1.1.45 Yes
Application cisco secure_desktop 3.1_base Yes
Application cisco secure_desktop 3.2.0.136 Yes
Application cisco secure_desktop 3.2.1.103 Yes
Application cisco secure_desktop 3.2.1.126 Yes
Application cisco secure_desktop 3.2_base Yes
Application cisco secure_desktop 3.3.0.118 Yes
Application cisco secure_desktop 3.3.0.151 Yes
Application cisco secure_desktop 3.3_base Yes
Application cisco secure_desktop 3.4.0373 Yes
Application cisco secure_desktop 3.4.1108 Yes
Application cisco secure_desktop 3.4.2048 Yes
Application cisco secure_desktop 3.4_base Yes
Application cisco secure_desktop 3.5.841 Yes
Application cisco secure_desktop 3.5.1077 Yes
Application cisco secure_desktop 3.5.2001 Yes
Application cisco secure_desktop 3.5.2003 Yes
Application cisco secure_desktop 3.5.2008 Yes
Application cisco secure_desktop 3.5_base Yes
Application cisco secure_desktop 3.6.181 Yes
Application cisco secure_desktop 3.6.185 Yes
Application cisco secure_desktop 3.6.1001 Yes
Application cisco secure_desktop 3.6.2002 Yes
Application cisco secure_desktop 3.6.3002 Yes
Application cisco secure_desktop 3.6.4021 Yes
Application cisco secure_desktop 3.6.5005 Yes
Application cisco secure_desktop 3.6.6020 Yes
Application cisco secure_desktop 3.6.6104 Yes
Application cisco secure_desktop 3.6.6203 Yes
Application cisco secure_desktop 3.6.6210 Yes
Application cisco secure_desktop 3.6.6228 Yes
Application cisco secure_desktop 3.6.6234 Yes
Application cisco secure_desktop 3.6.6249 Yes
Application cisco secure_desktop 3.6_base Yes

References