CVE-2006-7037
Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Mathcad 12 through 13.1 allows local users to bypass the security features by directly accessing or editing the XML representation of the worksheet with a text editor or other program, which allows attackers to (1) bypass password protection by replacing the password field with a hash of a known password, (2) modify timestamps to avoid detection of modifications, (3) remove locks by removing the "is-locked" attribute, and (4) view locked data, which is stored in plaintext.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Affected
- mathsoft/mathcad
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/2305
- http://www.securityfocus.com/archive/1/436441/30/4560/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27116
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27117
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27118
- http://securityreason.com/securityalert/2305
- http://www.securityfocus.com/archive/1/436441/30/4560/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27116
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27117
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27118
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.