SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2029

Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.

MEDIUM 5.8EPSS 1.37%

Does this matter?

Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.

Description

Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.37% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
cybozu/cybozu office · cybozu/cybozu dotsales
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.