Lucene search

K
cveMitreCVE-2007-2591
HistoryMay 11, 2007 - 4:20 a.m.

CVE-2007-2591

2007-05-1104:20:00
mitre
web.nvd.nist.gov
33
nokia
intellisync
mobile suite
vulnerability
remote
user account
modification
denial of service
nvd
cve-2007-2591

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.018

Percentile

88.4%

usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.

Affected configurations

Nvd
Node
nokiagroupwise_mobile_server
OR
nokiaintellisync_mobile_suiteMatch6.4.31.2
OR
nokiaintellisync_mobile_suiteMatch6.6.0.107
OR
nokiaintellisync_mobile_suiteMatch6.6.2.2
OR
nokiaintellisync_wireless_email_express
VendorProductVersionCPE
nokiagroupwise_mobile_server*cpe:2.3:a:nokia:groupwise_mobile_server:*:*:*:*:*:*:*:*
nokiaintellisync_mobile_suite6.4.31.2cpe:2.3:a:nokia:intellisync_mobile_suite:6.4.31.2:*:*:*:*:*:*:*
nokiaintellisync_mobile_suite6.6.0.107cpe:2.3:a:nokia:intellisync_mobile_suite:6.6.0.107:*:*:*:*:*:*:*
nokiaintellisync_mobile_suite6.6.2.2cpe:2.3:a:nokia:intellisync_mobile_suite:6.6.2.2:*:*:*:*:*:*:*
nokiaintellisync_wireless_email_express*cpe:2.3:a:nokia:intellisync_wireless_email_express:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.018

Percentile

88.4%

Related for CVE-2007-2591