CVE-2006-5807
published 2006-11-08CVE-2006-5807: Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the…
PriorityP412medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.34%
25.8th percentile
Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka "System Policy Evasion".
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_desktop | <= 3.1.1.33 | — |
| cisco | secure_desktop | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Secure Desktop
vendor_cisco·2006-11-08·CVSS 7.0
CVE-2006-5806 [HIGH] CWE-200 Multiple Vulnerabilities in Cisco Secure Desktop
Multiple Vulnerabilities in Cisco Secure Desktop
Cisco Secure Desktop (CSD) software is affected by three
vulnerabilities that may:
Cause information produced and accessed during an Internet browsing
session to be left behind on a computer after an SSL VPN session terminates.
Allow users to evade the system policy that prevents them from
leaving the Secure Desktop while a VPN connection is active.
Allow local users to elevate their privileges.
Cisco has made free software available to address these
vulnerabilities for affected customers. There are workarounds available to
mitigate the effects of some of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20061108-csd.
Cisco
Multiple Vulnerabilities in Cisco Secure Desktop
vendor_cisco
CVE-2006-5807 Multiple Vulnerabilities in Cisco Secure Desktop
CVE-2006-5807: Multiple Vulnerabilities in Cisco Secure Desktop
Cisco Secure Desktop (CSD) software is affected by three vulnerabilities that may: Cause information produced and accessed during an Internet browsing session to be left behind on a computer after an SSL VPN session terminates. Allow users to evade the system policy that prevents them from leaving the Secure Desktop while a VPN connection is active. Allow local users to elevate their privileges. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-200, CWE-264, CWE-200, CWE-264
Bug IDs: CSCsg05935, CSCsg11636, CSCsg29650, CSCsg05935
VulDB
Cisco Secure Desktop 3.1.1.45 Local Privilege Escalation (XFDB-30130 / SBV-13073)
vuldb·2026-04-27·CVSS 4.6
CVE-2006-5807 [MEDIUM] Cisco Secure Desktop 3.1.1.45 Local Privilege Escalation (XFDB-30130 / SBV-13073)
A vulnerability categorized as problematic has been discovered in Cisco Secure Desktop 3.1.1.45. Affected by this issue is some unknown functionality. Such manipulation leads to Local Privilege Escalation.
This vulnerability is listed as CVE-2006-5807. The attack must be carried out locally. There is no available exploit.
GHSA
GHSA-962p-8vcr-xqw4: Cisco Secure Desktop (CSD) before 3
ghsa_unreviewed·2022-05-01
CVE-2006-5807 [MEDIUM] GHSA-962p-8vcr-xqw4: Cisco Secure Desktop (CSD) before 3
Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka "System Policy Evasion".
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/22747http://securitytracker.com/id?1017195http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtmlhttp://www.osvdb.org/30307http://www.securityfocus.com/bid/20964http://www.vupen.com/english/advisories/2006/4409https://exchange.xforce.ibmcloud.com/vulnerabilities/30130http://secunia.com/advisories/22747http://securitytracker.com/id?1017195http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtmlhttp://www.osvdb.org/30307http://www.securityfocus.com/bid/20964http://www.vupen.com/english/advisories/2006/4409https://exchange.xforce.ibmcloud.com/vulnerabilities/30130
2006-11-08
Published