Vulnerabilities > CVE-2006-2709 - Remote Security vulnerability in Secure Elements Class 5 Enterprise vulnerability Management 2.8.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
secure-elements

Summary

Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2) forge messages to the server. Upgrade to version 2.8.1

Vulnerable Configurations

Part Description Count
Application
Secure_Elements
1