CVE-2010-0689
Estado: ModificadaAlta (10)—
The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.97%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://osvdb.org/62564
- http://secunia.com/advisories/38716
- http://sotiriu.de/adv/NSOADV-2010-003.txt
- http://sotiriu.de/demos/videos/nso-2010-003.html
- http://www.datev.de/info-db/1080162
- http://www.securityfocus.com/archive/1/509743/100/0/threaded
- http://www.securityfocus.com/bid/38415
- http://www.vupen.com/english/advisories/2010/0474
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56530
- http://osvdb.org/62564
- http://secunia.com/advisories/38716
- http://sotiriu.de/adv/NSOADV-2010-003.txt
- http://sotiriu.de/demos/videos/nso-2010-003.html
- http://www.datev.de/info-db/1080162
- http://www.securityfocus.com/archive/1/509743/100/0/threaded
- http://www.securityfocus.com/bid/38415
- http://www.vupen.com/english/advisories/2010/0474
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56530
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-0689",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-02-26T19:30:00.713",
"references": [
{
"url": "http://osvdb.org/62564",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/38716",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://sotiriu.de/adv/NSOADV-2010-003.txt",
"source": "cve@mitre.org"
},
{
"url": "http://sotiriu.de/demos/videos/nso-2010-003.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.datev.de/info-db/1080162",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/509743/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/38415",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0474",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/56530",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/62564",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/38716",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sotiriu.de/adv/NSOADV-2010-003.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sotiriu.de/demos/videos/nso-2010-003.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.datev.de/info-db/1080162",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/509743/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/38415",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/0474",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/56530",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors."
},
{
"lang": "es",
"value": "El método ExecuteExe en el control ActiveX DVBSExeCall v1.0.0.1 en DVBSExeCall.ocx en DATEV Base System (también conocido como Grundpaket Basis) permite a atacantes remotos a ejecutar comandos de su elección a través de vectores no especificados."
}
],
"lastModified": "2026-06-16T23:16:39.503",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:datev:base_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95D28E5E-985E-4465-80DD-627AF805DA2D"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/77.html\r\n\r\n\"CWE-77: Improper Sanitization of Special Elements used in a Command ('Command Injection')\"",
"sourceIdentifier": "cve@mitre.org"
}