« Volver al listado

CVE-2007-0829

Estado: ModificadaMedia (4.4)—

avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-0829",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.4,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-02-07T22:28:00.000",
  "references": [
    {
      "url": "http://osvdb.org/33114",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24068",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.avast.com/eng/avast-4-server-revision-history.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/22425",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0499",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32269",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/33114",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24068",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.avast.com/eng/avast-4-server-revision-history.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/22425",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0499",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/32269",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements."
    },
    {
      "lang": "es",
      "value": "avast! Server Edition anterior a la 4.7.726 no requiere una contraseña en ciertos contextos previstos, incluso cuando la contraseña ha sido  establecida, lo que permite a usuarios locales evitar los requerimientos de autenticación."
    }
  ],
  "lastModified": "2026-06-16T22:36:22.327",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:alwil:avast_antivirus:4.6.460:*:server:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C7C856F-6BAE-45F1-98AF-53B8D253885E"
            },
            {
              "criteria": "cpe:2.3:a:alwil:avast_antivirus:4.6.489:*:server:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4094691-E37D-4320-9978-17A1BEB68DE3"
            },
            {
              "criteria": "cpe:2.3:a:alwil:avast_antivirus:4.6.566:*:server:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71F0E1F5-1153-49AA-926E-8EEB530792AB"
            },
            {
              "criteria": "cpe:2.3:a:alwil:avast_antivirus:4.7.660:*:server:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "689355B2-4A72-4E20-BF16-F9AD17465D82"
            },
            {
              "criteria": "cpe:2.3:a:alwil:avast_antivirus:4.7.676:*:server:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96D9143C-B52C-420B-B4B2-AF021196CD45"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}