CVE-2010-4506
Estado: ModificadaMedia (6.2)—
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C
- Puntuación base: 6.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.77%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
- http://securityreason.com/securityalert/8065
- http://www.securityfocus.com/bid/46452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65439
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-007.txt
- http://securityreason.com/securityalert/8065
- http://www.securityfocus.com/bid/46452
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65439
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-007.txt
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-4506",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 1.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-02-07T21:00:01.887",
"references": [
{
"url": "http://securityreason.com/securityalert/8065",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/46452",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65439",
"source": "cve@mitre.org"
},
{
"url": "https://www.trustwave.com/spiderlabs/advisories/TWSL2010-007.txt",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/8065",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/46452",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/65439",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.trustwave.com/spiderlabs/advisories/TWSL2010-007.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a \"Save As\" dialog that is reachable from the \"Certificate Export\" wizard."
},
{
"lang": "es",
"value": "Passlogix v-GO (SSPR) y OEM antes de v7.0A permite a atacantes físicamente próximos ejecutar programas arbitrarios sin autenticación mediante la activación del de un certificado SSL no válido y el uso de la interfaz de Internet Explorer para navegar por el sistema de ficheros a través de un cuadro de diálogo \"Guardar como \" que es accesible desde el asistente de \"Exportación de certificado\""
}
],
"lastModified": "2026-06-16T23:24:56.480",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:passlogix_v-go_self-service_password_reset_and_oem:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EDC4DB1-2216-4853-AA28-9198314C4473"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}