{"api_version":"1","generated_at":"2026-07-23T11:15:09+00:00","cve":"CVE-2006-5807","urls":{"html":"https://cve.report/CVE-2006-5807","api":"https://cve.report/api/cve/CVE-2006-5807.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5807","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5807"},"summary":{"title":"CVE-2006-5807","description":"Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka \"System Policy Evasion\".","state":"PUBLISHED","assigner":"mitre","published_at":"2006-11-08 22:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1017195","name":"http://securitytracker.com/id?1017195","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Secure Desktop Bugs Let Local Users Gain LocalSystem Privileges, View Certain VPN Session Data, and Switch Out of the Secure Desktop - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4409","name":"http://www.vupen.com/english/advisories/2006/4409","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30130","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30130","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20964","name":"http://www.securityfocus.com/bid/20964","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Secure Desktop Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/22747","name":"http://secunia.com/advisories/22747","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Secure Desktop Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml","name":"http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco - Networking, Cloud, and Cybersecurity Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/30307","name":"http://www.osvdb.org/30307","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5807","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5807","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5807","vulnerable":"1","versionEndIncluding":"3.1.1.33","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"secure_desktop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:04:55.588Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"cisco-csd-application-security-bypass(30130)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30130"},{"name":"1017195","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017195"},{"name":"22747","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22747"},{"name":"30307","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/30307"},{"name":"20061108 Multiple Vulnerabilities in Cisco Secure Desktop","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml"},{"name":"ADV-2006-4409","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4409"},{"name":"20964","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20964"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka \"System Policy Evasion\"."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"cisco-csd-application-security-bypass(30130)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30130"},{"name":"1017195","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017195"},{"name":"22747","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22747"},{"name":"30307","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/30307"},{"name":"20061108 Multiple Vulnerabilities in Cisco Secure Desktop","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml"},{"name":"ADV-2006-4409","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4409"},{"name":"20964","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20964"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5807","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka \"System Policy Evasion\"."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cisco-csd-application-security-bypass(30130)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30130"},{"name":"1017195","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017195"},{"name":"22747","refsource":"SECUNIA","url":"http://secunia.com/advisories/22747"},{"name":"30307","refsource":"OSVDB","url":"http://www.osvdb.org/30307"},{"name":"20061108 Multiple Vulnerabilities in Cisco Secure Desktop","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml"},{"name":"ADV-2006-4409","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4409"},{"name":"20964","refsource":"BID","url":"http://www.securityfocus.com/bid/20964"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5807","datePublished":"2006-11-08T22:00:00.000Z","dateReserved":"2006-11-08T00:00:00.000Z","dateUpdated":"2024-08-07T20:04:55.588Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-11-08 22:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:secure_desktop:*:*:*:*:*:*:*:*","versionEndIncluding":"3.1.1.33","matchCriteriaId":"3E37AB27-7FAA-4F84-BA0F-2B88FB5C7F9B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5807","Ordinal":"1","Title":"CVE-2006-5807","CVE":"CVE-2006-5807","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5807","Ordinal":"1","NoteData":"Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka \"System Policy Evasion\".","Type":"Description","Title":"CVE-2006-5807"},{"CveYear":"2006","CveId":"5807","Ordinal":"2","NoteData":"2006-11-08","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5807","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}