« Volver al listado

CVE-2007-3537

Estado: ModificadaAlta (7.8)—

IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3537",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-07-03T20:30:00.000",
  "references": [
    {
      "url": "http://osvdb.org/37792",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25885",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www-1.ibm.com/support/docview.wss?uid=nas2742405285431729b86256e620067dc17",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24706",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35173",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37792",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25885",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-1.ibm.com/support/docview.wss?uid=nas2742405285431729b86256e620067dc17",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24706",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35173",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules."
    },
    {
      "lang": "es",
      "value": "IBM OS/400 (también conocido como i5/OS) V4R2M0 hasta V5R3M0 en máquinas iSeries envía respuestas a paquetes TCP SYN-FIN, lo cual permite a atacantes remotos obtener información sensible y posiblemente evitar reglas de cortafuegos."
    }
  ],
  "lastModified": "2026-06-16T22:42:14.640",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ibm:os_400:r520:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90930D05-EFEC-4E7A-8032-A781C0FEDE2F"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v4r2m0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A09FB84-0227-40FB-AAD4-9FBD6C677A92"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v4r3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7840B131-E836-478A-A6B5-5F19FB1B079D"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v4r4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5987D179-8327-4ABD-8D23-CCC9D0457FE5"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v4r5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22D354F5-4D07-4C4A-BE5F-F23A3BA11979"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v5r1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B8413DB-6A89-4CFE-A005-9D2FC9FBD114"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v5r2m0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E82033E-A936-4321-8E2D-5D545241A62D"
            },
            {
              "criteria": "cpe:2.3:o:ibm:os_400:v5r3m0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECEEF07F-0482-49B7-848E-206D02E81C61"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}