« Volver al listado

CVE-2005-2482

Estado: ModificadaMedia (5)—

The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing the Exploit command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2005-2482",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-08-07T04:00:00.000",
  "references": [
    {
      "url": "http://metasploit.com/archive/framework/msg00469.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/16318",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/18495",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/14455",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21705",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://metasploit.com/archive/framework/msg00469.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/16318",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/18495",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/14455",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21705",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the \"_Defanged\" environment option is checked when processing the Exploit command."
    },
    {
      "lang": "es",
      "value": "La función StateToOptions en msfweb de Metasploit Framework 2.4 y anteriores, cuando corre con la opción -D (modo defanged, desdentado) permite a atacantes modificar variables de entorno temporales antes de que la opción de entorno \"_Defanged\" sea comprobada cuando se procesa la orden Exploit."
    }
  ],
  "lastModified": "2026-06-16T22:14:58.640",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:metasploit:metasploit_framework:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DF37D89-2422-40ED-B56D-46C01001E995"
            },
            {
              "criteria": "cpe:2.3:a:metasploit:metasploit_framework:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC29C8C8-89B9-45C5-8987-2C6CD5B67A35"
            },
            {
              "criteria": "cpe:2.3:a:metasploit:metasploit_framework:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "429E8DD5-9539-459E-8B5D-0D640311FF5F"
            },
            {
              "criteria": "cpe:2.3:a:metasploit:metasploit_framework:2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D7D95C1-A62E-4737-B1A7-D99905E7DC27"
            },
            {
              "criteria": "cpe:2.3:a:metasploit:metasploit_framework:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9A806C7-696D-4256-A78F-8A8EAC793CDA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}