7.5
CVE-2006-0947
- EPSS 2.69%
- Veröffentlicht 01.03.2006 02:02:00
- Zuletzt bearbeitet 16.06.2026 22:21:36
- Erkennungen
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Thomson ≫ Speedtouch Version 516_5.3.2.6.0
Thomson ≫ Speedtouch Version 530_5.3.2.6.0
Thomson ≫ Speedtouch Version 536_5.3.2.6.0
Thomson ≫ Speedtouch Version 546_5.3.2.6.0
Thomson ≫ Speedtouch Version 576_5.3.2.6.0
Thomson ≫ Speedtouch Version 580_5.3.2.6.0
Thomson ≫ Speedtouch Version 585_5.3.2.6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.69% | 0.846 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/19069
http://securitytracker.com/id?1015688
http://www.securityfocus.com/archive/1/426186
http://www.securityfocus.com/bid/16839
http://www.vupen.com/english/advisories/2006/0765