CVE-2006-5966
Estado: ModificadaMedia (6.4)—
Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbitrary file existence and size via the ObtenerTamano method in the PAVPZ.SOS.1 ActiveX control.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.77%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-399
Referencias
- http://secunia.com/advisories/21763
- http://secunia.com/secunia_research/2006-64/advisory/
- http://www.securityfocus.com/archive/1/451864/100/0/threaded
- http://www.securityfocus.com/bid/21132
- http://www.vupen.com/english/advisories/2006/4536
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30317
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30318
- http://secunia.com/advisories/21763
- http://secunia.com/secunia_research/2006-64/advisory/
- http://www.securityfocus.com/archive/1/451864/100/0/threaded
- http://www.securityfocus.com/bid/21132
- http://www.vupen.com/english/advisories/2006/4536
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30317
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30318
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5966",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-17T22:07:00.000",
"references": [
{
"url": "http://secunia.com/advisories/21763",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/secunia_research/2006-64/advisory/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/archive/1/451864/100/0/threaded",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/bid/21132",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4536",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30317",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30318",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/advisories/21763",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/secunia_research/2006-64/advisory/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/451864/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21132",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4536",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30317",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30318",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-399"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbitrary file existence and size via the ObtenerTamano method in the PAVPZ.SOS.1 ActiveX control."
},
{
"lang": "es",
"value": "Panda ActiveScan 5.53.00, y otras versiones anteriores 5.54.01, permite a un atacante remoto (1) reiniciar el sistema usando el método Reinicializar en el controlador ActiveX de ActiveScan.1 o (2) determinar la existencia y tamaño de ficheros de su elección mediante el método ObtenerTamano del control ActiveX PAVPZ.SOS.1."
}
],
"lastModified": "2026-06-16T22:32:13.447",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:panda:activescan:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AE78593-0DC5-47C1-9624-5E304A7215B9"
},
{
"criteria": "cpe:2.3:a:panda:activescan:5.53.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA17277C-337F-4AE0-B92B-C572EEFCAF83"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
"evaluatorSolution": "This vulnerability is addressed in the following product release:\r\nPanda, ActiveScan, 5.54.01"
}