CVE-2013-3496
Estado: ModificadaAlta (7.2)—
Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-264
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-3496",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-05-22T13:29:56.170",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2013-05/0072.html",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2013-05/0072.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file."
},
{
"lang": "es",
"value": "Infotecs ViPNet Client v3.2.10 (15632) y anteriores, ViPNet Coordinator v3.2.10 (15632) y anteriores, ViPNet Personal Firewall v3.1 y anteriores y ViPNet SafeDisk v4.1 (0.5643) y anteriores usan permisos débiles (control total) para un directorio bajo %PROGRAMFILES%\\Infotecs, permitiendo a usuarios locales ganar privilegios mediante un troyano (1) fichero ejecutable o (2) DLL."
}
],
"lastModified": "2026-06-16T23:55:17.167",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:infotecs:vipnet_client:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C006E7D-B643-4E7F-BAFA-D74CD561EE28",
"versionEndIncluding": "3.2.10"
},
{
"criteria": "cpe:2.3:a:infotecs:vipnet_coordinator:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A647AAFF-8B3F-4B55-8A1A-E1322614D2BE",
"versionEndIncluding": "3.2.10"
},
{
"criteria": "cpe:2.3:a:infotecs:vipnet_personal_firewall:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3374283-8BC8-449D-A90D-43139C99FB31",
"versionEndIncluding": "3.1"
},
{
"criteria": "cpe:2.3:a:infotecs:vipnet_safedisk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83FD73F4-B5F3-4922-801E-FD0397E5C0E8",
"versionEndIncluding": "4.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}