« Volver al listado

CVE-2007-2023

Estado: ModificadaAlta (7.2)—

USB20.dll en el controlador de la memoria USB Secustick elimina las rutinas de autorización y acceso a ficheros, lo cual permite a usuarios locales evitar requisitos de validación a través de la alteración del valor de retorno de la función VerifyPassWord.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2023",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-04-13T18:19:00.000",
  "references": [
    {
      "url": "http://osvdb.org/41592",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://tweakers.net/reviews/682",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://tweakers.net/reviews/683",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41592",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://tweakers.net/reviews/682",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://tweakers.net/reviews/683",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "USB20.dll in Secustick USB flash drive decouples the authorization and file access routines, which allows local users to bypass authentication requirements by altering the return value of the VerifyPassWord function."
    },
    {
      "lang": "es",
      "value": "USB20.dll en el controlador de la memoria USB Secustick elimina las rutinas de autorización y acceso a ficheros, lo cual permite a usuarios locales evitar requisitos de validación a través de la alteración del valor de retorno de la función VerifyPassWord."
    }
  ],
  "lastModified": "2026-06-16T22:38:46.120",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:secustick:secustick_usb_flash_drive:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B6A25FA-93ED-4D06-9E58-397B94592CD3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}