Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cisco Secure Desktop Web Install ActiveX控件任意文件下载漏洞
Vulnerability Description
Cisco Secure Desktop(CSD)是美国思科(Cisco)公司的一款安全桌面产品,它可通过加密功能降低远程用户注销后或SSL VPN会话超时后Cookies、浏览器历史记录、临时文件和下载内容在系统上所遗留的风险。 Cisco Secure Desktop (CSD) 3.5.841之前版本中的Web Install ActiveX控件(CSDWebInstaller)不能正确验证已下载程序的签名。远程攻击者可借助特制web页面强制任意文件的下载和执行。
CVSS Information
N/A
Vulnerability Type
N/A