CVE-2010-2466
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.
S2 Security NetBox, probablemente v2.x v3.x, comoel usado en Linear eMerge 50 y 5000 y Sonitrol eAccess, no previene adecuadamente la descarga de datos backups, lo que permite a atacantes remotos obtener información sensible a través de peticiones para ficheros full_*.dar con nombres de ficheros predecibles.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-06-25 CVE Reserved
- 2010-06-25 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.darkreading.com/blog/archives/2010/04/attacking_door.html | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/228737 | Third Party Advisory |
|
http://www.securityinfowatch.com/Executives+Columns+%2526+Features/1316527?pageNum=2 | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/59826 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
S2sys Search vendor "S2sys" | Netbox Search vendor "S2sys" for product "Netbox" | 2.5 Search vendor "S2sys" for product "Netbox" and version "2.5" | - |
Affected
| ||||||
S2sys Search vendor "S2sys" | Netbox Search vendor "S2sys" for product "Netbox" | 3.3 Search vendor "S2sys" for product "Netbox" and version "3.3" | - |
Affected
| ||||||
Linearcorp Search vendor "Linearcorp" | Emerge 50 Search vendor "Linearcorp" for product "Emerge 50" | * | - |
Affected
| ||||||
Linearcorp Search vendor "Linearcorp" | Emerge 5000 Search vendor "Linearcorp" for product "Emerge 5000" | * | - |
Affected
| ||||||
Sonitrol Search vendor "Sonitrol" | Eaccess Search vendor "Sonitrol" for product "Eaccess" | * | - |
Affected
|