VulnerabilityModified
CVE-2006-2707
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.
MEDIUM 5.0EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- secure elements/class 5 enterprise vulnerability management
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20378
- http://securitytracker.com/id?1016184
- http://www.kb.cert.org/vuls/id/207337US Government Resource
- http://www.kb.cert.org/vuls/id/WDON-6QAPAL
- http://www.vupen.com/english/advisories/2006/2069
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26758
- http://secunia.com/advisories/20378
- http://securitytracker.com/id?1016184
- http://www.kb.cert.org/vuls/id/207337US Government Resource
- http://www.kb.cert.org/vuls/id/WDON-6QAPAL
- http://www.vupen.com/english/advisories/2006/2069
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26758
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.