6

CVE-2007-3462

Cross-site request forgery (CSRF) vulnerability in Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, allows remote attackers to execute commands as arbitrary users, and disable firewalling of the protected network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SofawareSafe At Office 500 Utm Versionembedded_ngx_7.0.39_ga
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.41% 0.819
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://labs.calyptix.com/CX-2007-04.php
Patch
http://labs.calyptix.com/CX-2007-04.txt
http://osvdb.org/37644
http://secunia.com/advisories/25822
http://www.securityfocus.com/archive/1/472290/100/0/threaded
http://www.securitytracker.com/id?1018317
http://www.sofaware.com/supportDownloads.aspx?boneId=182
http://www.vupen.com/english/advisories/2007/2364
https://exchange.xforce.ibmcloud.com/vulnerabilities/35093
https://exchange.xforce.ibmcloud.com/vulnerabilities/35094