CVE-2010-4506
Last modified
CVE-2010-4506 is a vulnerability of currently unknown severity. Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Passlogix V-Go Self-Service Password Reset And Oem | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4506?
How severe is CVE-2010-4506?
How do I fix CVE-2010-4506?
Are you affected by CVE-2010-4506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
