« Volver al listado

CVE-2006-7199

Estado: ModificadaAlta (8.5)—

EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a legitimate SiteKey server. NOTE: the vendor disputes the severity of the issue, stating that it is easier to monitor this attack than "attacks against static web pages."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-7199",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 8.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-04-30T23:19:00.000",
  "references": [
    {
      "url": "http://www.cr-labs.com/publications/SiteKey-20060718.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.cr-labs.com/publications/WhySiteKey-20060824.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.networkworld.com/newsletters/sec/2007/0402sec2.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.cr-labs.com/publications/SiteKey-20060718.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.cr-labs.com/publications/WhySiteKey-20060824.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.networkworld.com/newsletters/sec/2007/0402sec2.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in which an attacker-controlled server proxies authentication data to and from a legitimate SiteKey server.  NOTE: the vendor disputes the severity of the issue, stating that it is easier to monitor this attack than \"attacks against static web pages.\""
    },
    {
      "lang": "es",
      "value": "EMC RSA Security SiteKey permite a atacantes remotos mostrar la imagen correcta mediante un ataque de hombre-en-medio (MITM) en el cual un servidor controlado por el atacante hace de proxy para los datos de autenticación desde y hacia un servidor SiteKey legítimo. NOTA: el fabricante niega la severidad de este problema, afirmando que es más fácil monitorizar este ataque que \"ataques contra páginas web estáticas\"."
    }
  ],
  "lastModified": "2026-06-16T22:34:33.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:emc:rsa_security_sitekey:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C8C1263-8E82-4D21-B0BC-D521A1099834"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}