// For flags

CVE-2010-2468

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.

El S2 Security NetBox v2.x v3.x, como el usado en Linear eMerge 50 y 5000 y Sonitrol eAccess, usa un algoritmo hash débil para almacenar la contraseña de Administrador, lo que hace fácil a atacantes dependientes del contexto obtener privilegios de acceso para recuperando el texto limpio de esta contraseña.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-06-25 CVE Reserved
  • 2010-06-25 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
S2sys
Search vendor "S2sys"
Netbox
Search vendor "S2sys" for product "Netbox"
2.5
Search vendor "S2sys" for product "Netbox" and version "2.5"
-
Affected
S2sys
Search vendor "S2sys"
Netbox
Search vendor "S2sys" for product "Netbox"
3.3
Search vendor "S2sys" for product "Netbox" and version "3.3"
-
Affected
Linearcorp
Search vendor "Linearcorp"
Emerge 50
Search vendor "Linearcorp" for product "Emerge 50"
*-
Affected
Linearcorp
Search vendor "Linearcorp"
Emerge 5000
Search vendor "Linearcorp" for product "Emerge 5000"
*-
Affected
Sonitrol
Search vendor "Sonitrol"
Eaccess
Search vendor "Sonitrol" for product "Eaccess"
*-
Affected