CVE-2006-5808
published 2006-11-08CVE-2006-5808: The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.36%
27.9th percentile
The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka "Local Privilege Escalation".
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_desktop | <= 3.1.1.33 | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Secure Desktop
vendor_cisco·2006-11-08·CVSS 7.0
CVE-2006-5806 [HIGH] CWE-200 Multiple Vulnerabilities in Cisco Secure Desktop
Multiple Vulnerabilities in Cisco Secure Desktop
Cisco Secure Desktop (CSD) software is affected by three
vulnerabilities that may:
Cause information produced and accessed during an Internet browsing
session to be left behind on a computer after an SSL VPN session terminates.
Allow users to evade the system policy that prevents them from
leaving the Secure Desktop while a VPN connection is active.
Allow local users to elevate their privileges.
Cisco has made free software available to address these
vulnerabilities for affected customers. There are workarounds available to
mitigate the effects of some of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20061108-csd.
Cisco
Multiple Vulnerabilities in Cisco Secure Desktop
vendor_cisco
CVE-2006-5808 Multiple Vulnerabilities in Cisco Secure Desktop
CVE-2006-5808: Multiple Vulnerabilities in Cisco Secure Desktop
Cisco Secure Desktop (CSD) software is affected by three vulnerabilities that may: Cause information produced and accessed during an Internet browsing session to be left behind on a computer after an SSL VPN session terminates. Allow users to evade the system policy that prevents them from leaving the Secure Desktop while a VPN connection is active. Allow local users to elevate their privileges. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-200, CWE-264, CWE-200, CWE-264
Bug IDs: CSCsg05935, CSCsg11636, CSCsg29650, CSCsg05935
VulDB
Cisco Secure Desktop up to 3.1.1.44 Installation privileges management (XFDB-30128 / SBV-13074)
vuldb·2026-04-27·CVSS 4.6
CVE-2006-5808 [MEDIUM] Cisco Secure Desktop up to 3.1.1.44 Installation privileges management (XFDB-30128 / SBV-13074)
A vulnerability identified as problematic has been detected in Cisco Secure Desktop up to 3.1.1.44. This affects an unknown part of the component Installation. Performing a manipulation results in improper privilege management.
This vulnerability is cataloged as CVE-2006-5808. The attack must be initiated from a local position. Furthermore, there is an exploit available.
You should upgrade the affected component.
GHSA
GHSA-jw4c-mqg6-7wcm: The installation of Cisco Secure Desktop (CSD) before 3
ghsa_unreviewed·2022-05-01
CVE-2006-5808 [MEDIUM] GHSA-jw4c-mqg6-7wcm: The installation of Cisco Secure Desktop (CSD) before 3
The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka "Local Privilege Escalation".
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=442http://secunia.com/advisories/22747http://securitytracker.com/id?1017195http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtmlhttp://www.osvdb.org/30308http://www.securityfocus.com/bid/20964http://www.vupen.com/english/advisories/2006/4409https://exchange.xforce.ibmcloud.com/vulnerabilities/30128http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=442http://secunia.com/advisories/22747http://securitytracker.com/id?1017195http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtmlhttp://www.osvdb.org/30308http://www.securityfocus.com/bid/20964http://www.vupen.com/english/advisories/2006/4409https://exchange.xforce.ibmcloud.com/vulnerabilities/30128
2006-11-08
Published