CVE-2009-3339
Estado: ModificadaAlta (7.8)—
Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.41%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-3339",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": true,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-09-24T16:30:01.640",
"references": [
{
"url": "http://intevydis.com/vd-list.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/36574",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1022829",
"source": "cve@mitre.org"
},
{
"url": "http://intevydis.com/vd-list.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/36574",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1022829",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes."
},
{
"lang": "es",
"value": "Vulnerabilidad no especificada en McAfee Email y Web Security Appliance v5.1 VMtrial permite a los atacantes remotos leer arbitrariamente archivos a través de vectores desconocidos, como se demuestra en un cierto módulo en VulnDisco Pack Professional v8.9 hasta v8.11. NOTA: como en 20090917, esta información no tiene información de la acción. Sin embargo, debido a que el autor VulnDisco Pack es un investigador confiable, se le ha asignado un identificador CVE con fines de seguimiento."
}
],
"lastModified": "2026-06-16T23:11:24.900",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mcafee:email_and_web_security_appliance:5.1:-:vmtrial:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F74E6F29-D3AE-4FCD-B87C-4CFCA4795761"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:mcafee:email_and_web_security_appliance:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "400C7DFE-129B-4BDB-8437-933FAAE01A6D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"evaluatorComment": "Per http://www.mcafee.com/us/enterprise/products/virtualization_security/email_and_web_security_appliance_virtual.html\r\n\r\nExperience McAfee Email and Web Security Appliance through the power of virtualization\r\n\r\nWe’ve made it easier than ever to evaluate McAfee Email and Web Security Appliance, our email and web security appliance. Thanks to VMware virtualization technology, you can download a free 30-day software trial—with all of the features and functionality of the appliance. Install it on your server and experience uncompromising protection against spam, phishing, viruses, spyware, and more.",
"sourceIdentifier": "cve@mitre.org"
}