CVE-2010-3406
UnknownEPSS 0.35%
Last modified
CVE-2010-3406 is a vulnerability of currently unknown severity. Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Aix | 5.3 |
References
- http://aix.software.ibm.com/aix/efixes/security/sa_snap_advisory.ascPatch, Vendor Advisory
- http://secunia.com/advisories/41446Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2377Vendor Advisory
- http://aix.software.ibm.com/aix/efixes/security/sa_snap_advisory.ascPatch, Vendor Advisory
- http://secunia.com/advisories/41446Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2377Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3406?
Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.
How severe is CVE-2010-3406?
Severity scoring for CVE-2010-3406 is pending analysis. The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3406?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3399The js_InitRandom function in the JavaScript implementation …
- CVE-2010-3400The js_InitRandom function in the JavaScript implementation …
- CVE-2010-3402Untrusted search path vulnerability in IDM Computer Solution…
- CVE-2010-3403Untrusted search path vulnerability in Qualcomm eXtensible D…
- CVE-2010-3404Multiple SQL injection vulnerabilities in eshtery CMS (aka e…
- CVE-2010-3405Buffer overflow in sa_snap in the bos.esagent fileset in IBM…
- CVE-2010-3407Stack-based buffer overflow in the MailCheck821Address funct…
- CVE-2010-3408Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2010-3409Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2010-3410Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2010-3411Google Chrome before 6.0.472.59 on Linux does not properly h…
- CVE-2010-3412Race condition in the console implementation in Google Chrom…
Are you affected by CVE-2010-3406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
