CVE-2007-3464
Last modified
CVE-2007-3464 is a vulnerability of currently unknown severity. Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, does not require entry of the old password when changing the admin password, which might allow attackers to gain privileges by conducting a CSRF attack, making a password change on an unattended workstation, or other vectors.. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, does not require entry of the old password when changing the admin password, which might allow attackers to gain privileges by conducting a CSRF attack, making a password change on an unattended workstation, or other vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sofaware | Safe At Office 500 Utm | <= embedded_ngx_7.0.39_ga |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3464?
How severe is CVE-2007-3464?
How do I fix CVE-2007-3464?
Are you affected by CVE-2007-3464?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
