8.5
CVSSv2

CVE-2007-3464

Published: 27/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, does not require entry of the old password when changing the admin password, which might allow malicious users to gain privileges by conducting a CSRF attack, making a password change on an unattended workstation, or other vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

sofaware safe at office 500 utm