Lucene search

K
cve[email protected]CVE-2007-4600
HistoryOct 18, 2007 - 8:17 p.m.

CVE-2007-4600

2007-10-1820:17:00
CWE-264
web.nvd.nist.gov
24
mathcad
ptc
cve-2007-4600
security vulnerability
file access restrictions

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

25.3%

The “Protect Worksheet” functionality in Mathsoft Mathcad 12 through 13.1, and PTC Mathcad 14, implements file access restrictions via a protection element in a gzipped XML file, which allows attackers to bypass these restrictions by removing this element.

Affected configurations

NVD
Node
ptcmathcadMatch12
OR
ptcmathcadMatch13
OR
ptcmathcadMatch13.1
OR
ptcmathcadMatch14

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

25.3%

Related for CVE-2007-4600