CVE-2006-5393

MEDIUM

Cisco Secure Desktop - Out-of-Bounds Read

Title source: rule

Description

Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 20.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-125
Status draft

Affected Products (1)

cisco/secure_desktop

Timeline

Published Oct 18, 2006
Tracked Since Feb 18, 2026