« Volver al listado

CVE-2006-5271

Estado: ModificadaAlta (7.6)—

Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet, which causes stack corruption.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-5271",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-07-12T00:30:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/26029",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/threats/269.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/36098",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24863",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1018363",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2498",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31162",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://knowledge.mcafee.com/article/761/613364_f.SAL_Public.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26029",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/threats/269.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/36098",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24863",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1018363",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2498",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31162",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://knowledge.mcafee.com/article/761/613364_f.SAL_Public.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet, which causes stack corruption."
    },
    {
      "lang": "es",
      "value": "Desbordamiento inferior de un entero en el McAfee ePolicy Orchestrator 3.5 hasta el 3.6.1, el ProtectionPilot 1.1.1 y 1.5 y el Common Management Agent (CMA) 3.6.0.453 y versiones anteriores permite a atacantes remotos ejecutar código de su elección a través de paquetes UDP manipulados, lo que produce una corrupción de pila."
    }
  ],
  "lastModified": "2026-06-16T22:30:52.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mcafee:e-business_server:3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AA04BD6-C46B-4BD9-84A5-D56963D24FDC"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:e-business_server:3.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "737354DF-F5B6-49BA-9428-59DAFFF22942"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:protectionpilot:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D66F27F5-43A8-4E22-B1E4-D5C3261E4BA3"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:protectionpilot:1.1.1:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "340AF637-E84E-4326-8390-8055CFF1F76C"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:protectionpilot:1.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFCC653E-637A-41E8-95A6-ADBA7499CB96"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}