PT-2011-1586 · Microsoft+1 · Internet Explorer+1
Garrett Held
·
Published
2011-02-07
·
Updated
2017-08-17
·
CVE-2010-4506
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM versions prior to 7.0A
Description
The issue allows physically proximate attackers to execute arbitrary programs without authentication. This can be achieved by triggering the use of an invalid SSL certificate and utilizing the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog, which is reachable from the "Certificate Export" wizard.
Recommendations
For versions prior to 7.0A, update to version 7.0A or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Passlogix V-Go Self-Service Password Reset