Lucene search

K
cveMitreCVE-2010-4506
HistoryFeb 07, 2011 - 9:00 p.m.

CVE-2010-4506

2011-02-0721:00:01
CWE-310
mitre
web.nvd.nist.gov
21
cve-2010-4506
passlogix
v-go
self-service password reset
sspr
oem
invalid ssl certificate
internet explorer
filesystem
save as
certificate export.

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

25.7%

Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a “Save As” dialog that is reachable from the “Certificate Export” wizard.

Affected configurations

Nvd
Node
oraclepasslogix_v-go_self-service_password_reset_and_oemMatch7.0
VendorProductVersionCPE
oraclepasslogix_v-go_self-service_password_reset_and_oem7.0cpe:2.3:a:oracle:passlogix_v-go_self-service_password_reset_and_oem:7.0:*:*:*:*:*:*:*

CVSS2

6.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:H/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

25.7%

Related for CVE-2010-4506