MEDIUM · 5.0

CVE-2006-2707

Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clie...

Vulnerability Description

Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Secure ElementsClass 5 Enterprise Vulnerability Management2.8.0

References

FAQ

What is CVE-2006-2707?

CVE-2006-2707 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clie...

How severe is CVE-2006-2707?

CVE-2006-2707 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-2707?

Check the references section above for vendor advisories and patch information. Affected products include: Secure Elements Class 5 Enterprise Vulnerability Management.