CVE-2007-3464 Information

Description

Check Point SofaWare Safe@Office with firmware before Embedded NGX 7.0.45 GA does not require entry of the old password when changing the admin password which might allow attackers to gain privileges by conducting a CSRF attack making a password change on an unattended workstation or other vectors.

Reference

http://labs.calyptix.com/CX-2007-04.php http://labs.calyptix.com/CX-2007-04.txt http://osvdb.org/37644 http://www.securityfocus.com/archive/1/472290/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/35094

Share on: