SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2468

The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access…

HIGH 10.0EPSS 1.69%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
1.69% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
s2sys/netbox · linearcorp/emerge 50 · linearcorp/emerge 5000 · sonitrol/eaccess
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.