CVE-2010-4732
Estado: ModificadaAlta (9)—
cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
- Puntuación base: 9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.51%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-94
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2010-10/0002.html
- http://www.kb.cert.org/vuls/id/114560
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-316-01A.pdf
- http://archives.neohapsis.com/archives/bugtraq/2010-10/0002.html
- http://www.kb.cert.org/vuls/id/114560
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-316-01A.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-4732",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-02-15T01:00:01.727",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2010-10/0002.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/114560",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-10-316-01A.pdf",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2010-10/0002.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/114560",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-10-316-01A.pdf",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's GIF image file with a file containing this code, a different vulnerability than CVE-2009-4463."
},
{
"lang": "es",
"value": "cgi-bin/read.cgi en WebSCADA WS100 y WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, y Serial Ethernet Server SS100 en el IntelliCom NetBiter NB100 y plataformas NB200 permite a administradores autenticados de forma remota ejecutar código de su elección usando la acción config.html 2.conf para reemplazar el logo de la página principal que es una imagen GIF por un archivo que contiene este código, una vulnerabilidad distinta que CVE-2009-4463."
}
],
"lastModified": "2026-06-16T23:25:26.357",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:intellicom:netbiter_easyconnect_ec150:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC537D95-3DCD-4FD8-9CCE-61F70A818F4C"
},
{
"criteria": "cpe:2.3:h:intellicom:netbiter_modbus_rtu-tcp_gateway_mb100:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DBABB5F-235A-427D-B13E-7DCBFE7A4337"
},
{
"criteria": "cpe:2.3:h:intellicom:netbiter_serial_ethernet_server_ss100:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFD64BF7-5945-4CDE-84E3-D872081CB42F"
},
{
"criteria": "cpe:2.3:h:intellicom:netbiter_webscada_ws100:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCD25C93-C0EE-4EFD-8066-53CE3840BF1B"
},
{
"criteria": "cpe:2.3:h:intellicom:netbiter_webscada_ws200:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01FE6CE4-81D4-47B9-A859-92E267712B49"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:intellicom:netbiter_nb100:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD774110-E3E9-4A65-9B8D-5A62B0AEB410"
},
{
"criteria": "cpe:2.3:h:intellicom:netbiter_nb200:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "769218F4-5A0A-42E6-8DB4-F133AF5741E8"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}