CVE-2015-0691
published 2015-04-17CVE-2015-0691: A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.07%
86.1th percentile
A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7x5j-vqwr-gg77: A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a c
ghsa_unreviewed·2022-05-17
CVE-2015-0691 [HIGH] CWE-78 GHSA-7x5j-vqwr-gg77: A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a c
A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001.
Cisco
Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability
vendor_cisco·2015-04-15·CVSS 9.3
CVE-2015-0691 [CRITICAL] CWE-78 Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability
Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability
A vulnerability in a Cisco-signed Java Archive (JAR)
executable Cache Cleaner component of Cisco Secure Desktop could allow an
unauthenticated, remote attacker to execute arbitrary commands on the
client host where the affected .jar file is executed. Command execution would
occur with the privileges of the user.
The Cache Cleaner feature has been deprecated since November 2012.
There is no fixed software for this vulnerability. Cisco Secure Desktop packages that include the affected .jar files have been removed and are no longer available for download.
Because Cisco does not control all existing Cisco Secure Desktop packages, customers are advised to ensure that their Java blacklist controls have been updated to avoid p
Cisco
Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability
vendor_cisco
CVE-2015-0691 Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability
CVE-2015-0691: Cisco Secure Desktop Cache Cleaner Command Execution Vulnerability
A vulnerability in a Cisco-signed Java Archive (JAR) executable Cache Cleaner component of Cisco Secure Desktop could allow an unauthenticated, remote attacker to execute arbitrary commands on the client host where the affected . jar file is executed. Command execution would occur with the privileges of the user. The Cache Cleaner feature has been deprecated since November 2012. There is no fixed software for this vulnerability. Cisco Secure Desktop packages that include the affected .jar files have been removed and are no longer available for download. Because Cisco does not control all existing Cisco Secure Desktop packages, customers are advised to ensure that their Java blacklist controls have been update
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-17
Published