René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

107 lines
3.3 KiB
JSON

{
"id": "CVE-2007-2240",
"sourceIdentifier": "cret@cert.org",
"published": "2007-08-15T19:17:00.000",
"lastModified": "2018-10-12T21:43:41.223",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download."
},
{
"lang": "es",
"value": "El control ActiveX IBM Lenovo Access Support acpRunner, como el distribuido en acpcontroller.dll anterior a 1.2.8.0 y posiblemente acpir.dll anterior a 1.0.0.9 (Automated Solutions 1.0 anterior a fix pack 1), no valida adecuadamente las firmas digitales del software descargado, lo cual hace m\u00e1s f\u00e1cil para atacantes remotos falsificar una descarga."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 5.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:h:lenovo:access_support:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22E333F5-25FB-4F86-9DB2-E32C5F7041A8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:lenovo:automated_solutions:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "53FE9F21-4C54-4F7A-9F15-45281A21EBB1"
}
]
}
]
}
],
"references": [
{
"url": "http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/570705",
"source": "cret@cert.org",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.securityfocus.com/bid/25311",
"source": "cret@cert.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2882",
"source": "cret@cert.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045",
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36028",
"source": "cret@cert.org"
}
]
}