SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-5008

Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.

LOW 2.1EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS
0.35% probability · 29th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
cisco/secure desktop
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.