Lucene search

K
cveMitreCVE-2013-5701
HistoryOct 03, 2013 - 8:55 p.m.

CVE-2013-5701

2013-10-0320:55:04
CWE-264
mitre
web.nvd.nist.gov
23
cve-2013-5701
vulnerabilities
watchguard log collector
watchguard webblocker server
local users
privilege escalation
trojan horse
bin directory

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

27.6%

Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) in WatchGuard Server Center 11.7.4, 11.7.3, and possibly earlier allow local users to gain privileges via a Trojan horse wgpr.dll file in the application’s bin directory.

Affected configurations

Nvd
Node
watchguardserver_centerRange11.7.4
OR
watchguardserver_centerMatch11.7.3
VendorProductVersionCPE
watchguardserver_center*cpe:2.3:a:watchguard:server_center:*:*:*:*:*:*:*:*
watchguardserver_center11.7.3cpe:2.3:a:watchguard:server_center:11.7.3:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

27.6%