5
CVE-2010-2465
- EPSS 2.46%
- Veröffentlicht 25.06.2010 21:30:01
- Zuletzt bearbeitet 16.06.2026 23:20:48
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.46% | 0.823 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://blip.tv/file/3414004
http://www.slideshare.net/shawn_merdinger/we-dont-need-no-stinkin-badges-hacking-electronic-door-access-controllersquot-shawn-merdinger-carolinacon
http://osvdb.org/65757
http://secunia.com/advisories/40374
http://www.darkreading.com/blog/archives/2010/04/attacking_door.html
http://www.kb.cert.org/vuls/id/251133
http://www.kb.cert.org/vuls/id/MAPG-83TQL8
http://www.securityfocus.com/bid/41134
http://www.securityinfowatch.com/Executives+Columns+%2526+Features/1316527?pageNum=2