CVE-2010-0589
N/A
N/A
Summary
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtml
- http://www.zerodayinitiative.com/advisories/ZDI-10-072/
- http://www.securityfocus.com/bid/39478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57812
- http://securitytracker.com/id?1023881
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtml
- http://www.zerodayinitiative.com/advisories/ZDI-10-072/
- http://www.securityfocus.com/bid/39478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/57812
- http://securitytracker.com/id?1023881
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.