CVE-2005-2790
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- bfcommand and control software/bfcc · bfcommand and control software/bfvcc
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/bfccown-adv.txtExploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=112534155318828&w=2
- http://secunia.com/advisories/16629/Vendor Advisory
- http://www.securityfocus.com/bid/14690Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22057
- http://aluigi.altervista.org/adv/bfccown-adv.txtExploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=112534155318828&w=2
- http://secunia.com/advisories/16629/Vendor Advisory
- http://www.securityfocus.com/bid/14690Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22057
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.