CVE-2015-0691 (CNNVD-201504-375)
CRITICAL
中文标题:
Cisco Secure Desktop Cache Cleaner JAR文件安全漏洞
英文标题:
A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remo...
CVSS分数:
9.3
发布时间:
2015-04-17 01:00:00
漏洞类型:
授权问题
状态:
PUBLISHED
数据质量分数:
0.30
数据版本:
v3
漏洞描述
中文描述:
Cisco Secure Desktop(CSD)是美国思科(Cisco)公司的一款安全桌面产品,它可通过加密功能降低远程用户注销后或SSL VPN会话超时后Cookies、浏览器历史记录、临时文件和下载内容在系统上所遗留的风险。 CSD的Cache Cleaner中分发的Cisco JAR文件中存在安全漏洞。远程攻击者可借助特制的Web站点利用该漏洞执行任意命令。
英文描述:
A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001.
CWE类型:
CWE-78
CWE-264
标签:
(暂无数据)
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | secure_desktop | 3.0_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.0_base:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.1.0.31 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.1.0.31:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.1.1 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.1.1:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.1.1.45 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.1.1.45:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.1_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.1_base:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.2.0.136 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.2.0.136:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.2.1.103 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.2.1.103:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.2.1.126 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.2.1.126:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.2_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.2_base:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.3.0.118 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.3.0.118:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.3.0.151 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.3.0.151:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.3_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.3_base:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.4.0373 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.4.0373:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.4.1108 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.4.1108:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.4.2048 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.4.2048:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.4_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.4_base:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.5.841 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.5.841:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.5.1077 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.5.1077:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.5.2001 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.5.2001:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.5.2003 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.5.2003:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.5.2008 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.5.2008:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.5_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.5_base:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.181 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.181:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.185 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.185:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.1001 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.1001:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.2002 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.2002:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.3002 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.3002:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.4021 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.4021:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.5005 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.5005:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6020 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6020:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6104 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6104:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6203 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6203:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6210 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6210:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6228 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6228:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6234 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6234:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6.6249 | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6.6249:*:*:*:*:*:*:*
|
| cisco | secure_desktop | 3.6_base | - | - |
cpe:2.3:a:cisco:secure_desktop:3.6_base:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
CVSS评分详情
9.3
CRITICAL
CVSS向量:
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS版本:
2.0
机密性
COMPLETE
完整性
COMPLETE
可用性
COMPLETE
时间信息
发布时间:
2015-04-17 01:00:00
修改时间:
2024-08-06 04:17:32
创建时间:
2025-11-11 15:33:58
更新时间:
2025-11-11 15:51:56
利用信息
暂无可利用代码信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2015-0691 |
2025-11-11 15:18:53 | 2025-11-11 07:33:58 |
| NVD | nvd_CVE-2015-0691 |
2025-11-11 14:54:49 | 2025-11-11 07:42:41 |
| CNNVD | cnnvd_CNNVD-201504-375 |
2025-11-11 15:09:33 | 2025-11-11 07:51:56 |
版本与语言
当前版本:
v3
主要语言:
EN
支持语言:
EN
ZH
安全公告
暂无安全公告信息
变更历史
v3
CNNVD
2025-11-11 15:51:56
vulnerability_type: 未提取 → 授权问题; cnnvd_id: 未提取 → CNNVD-201504-375; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-201504-375
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2
NVD
2025-11-11 15:42:41
severity: SeverityLevel.MEDIUM → SeverityLevel.CRITICAL; cvss_score: 未提取 → 9.3; cvss_vector: NOT_EXTRACTED → AV:N/AC:M/Au:N/C:C/I:C/A:C; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 37; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 37
- data_sources: ['cve'] -> ['cve', 'nvd']