« Volver al listado

CVE-2012-4670

Estado: ModificadaMedia (6.4)—

Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4670",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-25T16:55:01.417",
  "references": [
    {
      "url": "http://www.tigase.org/content/finally-version-510-final-available",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://xmpp.org/resources/security-notices/server-dialback/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77985",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://projects.tigase.org/projects/tigase-server/repository/revisions/2953/diff",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tigase.org/content/finally-version-510-final-available",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://xmpp.org/resources/security-notices/server-dialback/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77985",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://projects.tigase.org/projects/tigase-server/repository/revisions/2953/diff",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response."
    },
    {
      "lang": "es",
      "value": "Tigase XMPP Server antes de v5.1.0 no comprueba que se presente una solicitud para una respuesta XMPP Server Dialback, lo que permite a servidores remotos de XMPP falsificar dominios a través (1) Verify Response o (2) Authorization Response."
    }
  ],
  "lastModified": "2026-06-16T23:45:32.757",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tigase:tigase_xmpp_server:*:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A22266A-B257-40D6-B24D-5AA752F7F50D",
              "versionEndIncluding": "5.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}