CVE-2010-2466: Medium severity lenels2 netbox vulnerability
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full.dar files with predictable filenames.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2466?
CVE-2010-2466 is classified as a medium-severity vulnerability that allows unauthorized access to database backups.
How do I fix CVE-2010-2466?
To fix CVE-2010-2466, ensure that proper access controls are implemented to restrict access to sensitive files like full_*.dar.
What software versions are affected by CVE-2010-2466?
CVE-2010-2466 affects S2 Security NetBox versions 2.x and 3.x, including specific models of the Linear eMerge 50 and 5000, and Sonitrol eAccess.
What kind of information can be leaked due to CVE-2010-2466?
CVE-2010-2466 could expose sensitive information found in database backup files, which can be exploited by remote attackers.
Is there a patch available for CVE-2010-2466?
Check with the vendor for any security updates or patches that address CVE-2010-2466 to mitigate the risks.