SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-2707

Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.

MEDIUM 5.0EPSS 1.14%

Does this matter?

Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.

Description

Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.14% probability · 65th percentile
CISA KEV
Not listed
Affected
secure elements/class 5 enterprise vulnerability management
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.