« Volver al listado

CVE-2007-1666

Estado: ModificadaAlta (10)—

The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-1666",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-03-24T20:19:00.000",
  "references": [
    {
      "url": "http://labs.idefense.com/intelligence/vulnerabilities/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24635",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/33523",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/23114",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1017815",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1089",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33190",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://labs.idefense.com/intelligence/vulnerabilities/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24635",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/33523",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/23114",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1017815",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/1089",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33190",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions."
    },
    {
      "lang": "es",
      "value": "La función processor_request en el servidor depurador para DataRescue IDA Pro versiones 5.0 y 5.1, no comprueba que la autenticación ha tenido lugar antes de invocar la función perform_request, lo que permite a atacantes realizar acciones no autorizadas."
    }
  ],
  "lastModified": "2026-06-16T22:38:04.287",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:datarescue:ida_pro:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A34ED464-292E-44ED-8E8C-565A03AB57E1"
            },
            {
              "criteria": "cpe:2.3:a:datarescue:ida_pro:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83DC1C0D-3534-4A97-B657-B958CDF5DAE7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "This vulnerability has been addressed in the following product updates. \r\n\r\nDataRescue IDA Pro 5.0 \r\n\r\nDataRescue ida_remdeb_fix_22032007.zip\r\nhttp://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip\r\n\r\n\r\nDataRescue IDA Pro 5.1 \r\n\r\nDataRescue ida_remdeb_fix_22032007.zip\r\nhttp://www.datarescue.com/freefiles/ida_remdeb_fix_22032007.zip\r\n"
}