Lucene search

K
cveMitreCVE-2010-2029
HistoryMay 24, 2010 - 7:30 p.m.

CVE-2010-2029

2010-05-2419:30:01
CWE-264
mitre
web.nvd.nist.gov
26
cve-2010-2029
cybozu office
ktai
dotsales
authentication bypass
remote access
sensitive information
id theft

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.005

Percentile

76.8%

Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user’s cell phone.

Affected configurations

Nvd
Node
cybozucybozu_officeMatch7-ktai
Node
cybozucybozu_dotsales
VendorProductVersionCPE
cybozucybozu_office7cpe:2.3:a:cybozu:cybozu_office:7:-:ktai:*:*:*:*:*
cybozucybozu_dotsales*cpe:2.3:a:cybozu:cybozu_dotsales:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.005

Percentile

76.8%

Related for CVE-2010-2029