Vulnerability Name: | CCN-59062 | ||||||
Published: | 2010-06-01 | ||||||
Updated: | 2010-06-01 | ||||||
Summary: | Kerio MailServer and Kerio WinRoute Firewall could allow a remote attacker to obtain sensitive information, caused by an error in the Administration Console. An attacker with complete admin permissions could exploit this vulnerability to read or corrupt arbitrary files on the system. | ||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: SA39995 Kerio Products Administration Console Unspecified Vulnerability Source: CCN Type: Kerio Web site Kerio MailServer Download Source: CCN Type: KSEC-2010-06-01-01 Product administrator may read or corrupt arbitrary file on the server Source: CCN Type: OSVDB ID: 65114 Kerio Multiple Products Administration Console Unspecified Arbitrary File Access Source: CCN Type: BID-40505 Multiple Kerio Products Administration Console File Disclosure and Corruption Vulnerability Source: XF Type: UNKNOWN kerio-admin-console-info-disclosure(59062) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |