Lucene search

K
cveMitreCVE-2010-2467
HistoryJun 25, 2010 - 9:30 p.m.

CVE-2010-2467

2010-06-2521:30:01
CWE-255
mitre
web.nvd.nist.gov
29
cve-2010-2467
s2 security netbox
linear emerge
sonitrol eaccess
ftp server
database backups
remote attackers
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.014

Percentile

86.7%

The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.

Affected configurations

Nvd
Node
s2sysnetboxMatch2.5
OR
s2sysnetboxMatch3.3
OR
s2sysnetboxMatch4.0
Node
linearcorpemerge_50
OR
linearcorpemerge_5000
Node
sonitroleaccess
VendorProductVersionCPE
s2sysnetbox2.5cpe:2.3:h:s2sys:netbox:2.5:*:*:*:*:*:*:*
s2sysnetbox3.3cpe:2.3:h:s2sys:netbox:3.3:*:*:*:*:*:*:*
s2sysnetbox4.0cpe:2.3:h:s2sys:netbox:4.0:*:*:*:*:*:*:*
linearcorpemerge_50*cpe:2.3:h:linearcorp:emerge_50:*:*:*:*:*:*:*:*
linearcorpemerge_5000*cpe:2.3:h:linearcorp:emerge_5000:*:*:*:*:*:*:*:*
sonitroleaccess*cpe:2.3:h:sonitrol:eaccess:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.014

Percentile

86.7%

Related for CVE-2010-2467