« Volver al listado

CVE-2010-2029

Estado: ModificadaMedia (5.8)—

Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-2029",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-05-24T19:30:01.457",
  "references": [
    {
      "url": "http://cybozu.co.jp/products/dl/notice/detail/0034.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN87730223/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000016.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/39508",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/63933",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/57976",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://cybozu.co.jp/products/dl/notice/detail/0034.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN87730223/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000016.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/39508",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/63933",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/57976",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone."
    },
    {
      "lang": "es",
      "value": "Cybozu Office 7 Ktai y Dotsales no restringen el acceso a la página de inicio de sesión apropiadamente; lo que permite, a atacantes remotos, evitar la  autenticación y obtener o modificar información confidencial a través del ID único del número de telefóno móvil del usuario."
    }
  ],
  "lastModified": "2026-06-16T23:19:50.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cybozu:cybozu_office:7:-:ktai:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "941E9A1B-1510-4AE1-9E56-5EF33EC9104A"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cybozu:cybozu_dotsales:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "313EE48E-33E5-4363-9394-762887056DCA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}