« Back to list

CVE-2006-4184

Status: ModifiedMedium (4.9)—

SmartLine DeviceLock before 5.73 Build 305 does not properly enforce access control lists (ACL) in raw mode, which allows local users to bypass NTFS controls and obtain sensitive information.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2006-4184",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-08-17T00:04:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/21494",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1392",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.protect-me.com/dl/whatsnew.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443193/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19500",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28384",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/21494",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/1392",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.protect-me.com/dl/whatsnew.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/443193/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19500",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28384",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SmartLine DeviceLock before 5.73 Build 305 does not properly enforce access control lists (ACL) in raw mode, which allows local users to bypass NTFS controls and obtain sensitive information."
    },
    {
      "lang": "es",
      "value": "SmartLine DeviceLock anterior a 5.73 Build 305 no hace cumplir adecuadamente las listas de control de acceso (ACL) en modo en sucio (raw mode), lo que permite a usuarios locales evitar los controles NTFS y obtener información sensible."
    }
  ],
  "lastModified": "2026-06-16T22:28:33.983",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:smartline:devicelock:5.72:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1D794CD-EC4C-4727-B4D4-1E681584FFC8"
            },
            {
              "criteria": "cpe:2.3:a:smartline:devicelock:5.73_build_288:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AD9EE03-86BD-47AB-A5B5-AC195C43CAE0"
            },
            {
              "criteria": "cpe:2.3:a:smartline:devicelock:5.73_build_300:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80877EBE-D1A9-441D-A18A-8C32729200F9"
            },
            {
              "criteria": "cpe:2.3:a:smartline:devicelock:5.73_build_303:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3DD70764-AF9E-46F2-B177-EB09059A8489"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "This vulnerability is addressed in the following product releases:\r\nSmartLine, DeviceLock, 5.73 Build 305 \r\nSmartLine, DeviceLock, 6.0"
}