Show plain JSON{"id": "CVE-2016-10710", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": true, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.1, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.2, "exploitabilityScore": 2.8}]}, "published": "2018-01-25T23:29:00.240", "references": [{"url": "http://threat.tevora.com/biscom-secure-file-transfer-arbitrary-file-download/", "tags": ["Exploit", "Technical Description", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://threat.tevora.com/biscom-secure-file-transfer-arbitrary-file-download/", "tags": ["Exploit", "Technical Description", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests. Version 5.0.1050 contains the fix."}, {"lang": "es", "value": "Biscom Secure File Transfer (SFT) desde la versi\u00f3n 5.0.1000 hasta la 5.0.1048 no valida el valor dataFieldId y utiliza n\u00fameros secuenciales, lo que permite que los usuarios autenticados remotos sobrescriban o lean archivos mediante peticiones manipuladas. La versi\u00f3n 5.0.1050 contiene la soluci\u00f3n."}], "lastModified": "2024-11-21T02:44:33.947", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:biscom:secure_file_transfer:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7DE2CAB-2EE4-40FB-AC10-D3797E07E074", "versionEndIncluding": "5.0.1048", "versionStartIncluding": "5.0.1000"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}