« Volver al listado

CVE-2007-4409

Estado: ModificadaMedia (5.1)—

Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arrives.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4409",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-18T21:17:00.000",
  "references": [
    {
      "url": "http://osvdb.org/46714",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/3031",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/476285/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/25285",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35995",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/46714",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/3031",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/476285/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/25285",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35995",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arranging for ops privilege to be granted before the mode arrives."
    },
    {
      "lang": "es",
      "value": "Condición de carrera en ircu 2.10.12.01 hasta 2.10.12.05 permite a atacantes remotos establecer una nueva contraseña de administrador (Apass) durante una ráfaga de red (netburst) provocando que el privilegio de operador (ops) sea otorgado antes de que llegue el modo."
    }
  ],
  "lastModified": "2026-06-16T22:44:01.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:universal_ircd:ircu:2.10.12.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E155257-13BC-4EE2-A67D-50DA7D8781C1"
            },
            {
              "criteria": "cpe:2.3:a:universal_ircd:ircu:2.10.12.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAB40F55-AEB9-4C11-9DD1-CEE82B8D5677"
            },
            {
              "criteria": "cpe:2.3:a:universal_ircd:ircu:2.10.12.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0AD3199-0273-4B7C-9DBA-C93B38A9B998"
            },
            {
              "criteria": "cpe:2.3:a:universal_ircd:ircu:2.10.12.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0DEFEDA-4060-4991-8B91-BE2A6690E3CE"
            },
            {
              "criteria": "cpe:2.3:a:universal_ircd:ircu:2.10.12.05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "430903CF-7B43-4C85-91F7-9FF3A0BF5453"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}