2024-07-14 02:06:08 +00:00

127 lines
3.5 KiB
JSON

{
"id": "CVE-2007-4415",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-08-18T21:17:00.000",
"lastModified": "2018-10-15T21:35:14.997",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe."
},
{
"lang": "es",
"value": "Cisco VPN Client sobre Windows anterior a 5.0.01.0600, y la versi\u00f3n 5.0.01.0600 InstallShield (IS), utiliza permisos d\u00e9biles para cvpnd.exe (modificando los privilegios en Interactive Users), lo cual permite a usuarios locales ganar privilegios a trav\u00e9s de un cvpnd.exe modificado."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.1,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:vpn_client:*:*:windows:*:*:*:*:*",
"versionEndIncluding": "5.0.01",
"matchCriteriaId": "17848271-64A7-4807-B1FB-01A66E91E8CB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:vpn_client:5.0.01.0600:*:*:*:*:*:*:*",
"matchCriteriaId": "58FB3744-3107-410F-8E03-228060A95018"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/26459",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://securityreason.com/securityalert/3023",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018573",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.cisco.com/warp/public/707/cisco-sa-20070815-vpnclient.shtml",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.securityfocus.com/archive/1/476812/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25332",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2007/2903",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36032",
"source": "cve@mitre.org"
}
]
}