CVE-2010-0589
Summary
| CVE | CVE-2010-0589 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-15 17:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Desktop | 3.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1.27 | All | All | All |
| Application | Cisco | Secure Desktop | 3.1.1.33 | All | All | All |
| Application | Cisco | Secure Desktop | 3.2 | All | All | All |
| Application | Cisco | Secure Desktop | 3.2.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.3 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4.1 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4.2 | All | All | All |
| Application | Cisco | Secure Desktop | 3.4.2048 | All | All | All |
| Application | Cisco | Secure Desktop | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Security Advisory: Cisco Secure Desktop ActiveX Control Code Execution Vulnerability - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Secure Desktop ActiveX Control Executable File Arbitrary File Download Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Cisco Secure Desktop ActiveX Control Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.