CVE-2005-2579: High severity Nortel Contivity vulnerability
Published Aug 16, 2005
·Updated
Nortel Contivity VPN Client V0501.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the File Open dialog box.
Affected Software
1 affected component
Nortel Contivity=v05_01.030
Event History
Aug 16, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2579?
CVE-2005-2579 is considered a moderate severity vulnerability due to its potential to allow local privilege escalation.
2
How do I fix CVE-2005-2579?
To fix CVE-2005-2579, upgrade to a version of the Nortel Contivity VPN Client that does not have this vulnerability.
3
What software is affected by CVE-2005-2579?
CVE-2005-2579 specifically affects the Nortel Contivity VPN Client version 5.01.030.
4
What type of vulnerability is CVE-2005-2579?
CVE-2005-2579 is a local privilege escalation vulnerability.
5
Can exploitation of CVE-2005-2579 be easily performed?
Exploitation of CVE-2005-2579 requires local access to the system, which can pose a risk if best security practices are not followed.