« Volver al listado

CVE-2010-1906

Estado: ModificadaAlta (7.2)—

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-1906",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-05-12T11:46:31.580",
  "references": [
    {
      "url": "http://secunia.com/advisories/39752",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/602801",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/511176/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wintercore.com/downloads/rootedcon_0day.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/39752",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/602801",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/511176/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wintercore.com/downloads/rootedcon_0day.pdf",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\\\.\\pipe\\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service."
    },
    {
      "lang": "es",
      "value": "tgsrv.exe en Repair Service en Consona Dynamic Agent, Repair Manager, Subscriber Activation, y Subscriber Agent se basa en un campo de marca de tiempo previsible para validar la entrada a tuberia llamada \\\\.\\pipe\\__RepairService_pipe__company, lo cual permite a usuarios remotos autenticados ejecutar cualquier código mediante la obtención de la hora actual de (1) tcpip.sys o (2) un servicio SMB2."
    }
  ],
  "lastModified": "2026-06-16T23:19:33.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:consona:consona_dynamic_agent:-:-:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E86DC4D-1E5C-4284-AA49-FD5F3AA9056A"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_dynamic_agent:-:-:marketing:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76A93E2B-D458-43A4-A4A5-9FA0981B72EF"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_dynamic_agent:-:-:support:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1AAF4CD-3D1A-4C44-8338-4F614E4645CB"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_repair_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30CE5337-79F6-4C02-A5F4-81A29257D580"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_subscriber_activation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89519FBD-EF43-45E1-80F1-B9C7372137D3"
            },
            {
              "criteria": "cpe:2.3:a:consona:consona_subscriber_agent:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06F48C4A-0232-4375-888D-CE8EB9E833AF"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D56B932B-9593-44E2-B610-E4EB2143EB21"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3852BB02-47A1-40B3-8E32-8D8891A53114"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}