Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-5460

EPSS 1.03% · P77
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-5460

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained by (1) sniffing or (2) spoofing the docking process.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft ActiveSync弱口令混淆信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft ActiveSync是用于同步计算机与PDA的应用程序。 ActiveSync设备建立连接口令交换的过程实现上存在漏洞,攻击者可能利用此漏洞获取口令信息。 插入到USB口时设备会使用类似于标准网络接口的连接,获得IP地址后设备会通过RAPI在990/TCP端口初始化与主机的通讯,这个过程也会经历一个小型的握手例程,如果合适的话,会对主机挑战设备PIN或口令。用户提供了主机的PIN/口令后,会通过XOR与E9固定密钥进行混淆,然后通过USB网络连接发送给设备进行验证。 这个过程会产生两个
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-5460

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-5460

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-10-15 · 8 CVEs total

CVE-2007-5465doop CMS 未明组件目录遍历漏洞
CVE-2007-5466eXtremail多个远程溢出漏洞
CVE-2007-5467Extremail pop3_port USER指令拒绝服务漏洞
CVE-2007-5462Sun Solaris RPC服务库librpcsvc(3LIB)拒绝服务漏洞
CVE-2007-5463ViArt Shop 'Ideal_Process.PHP' 目录遍历漏洞
CVE-2007-5464Live for Speed皮肤名称远程栈溢出漏洞
CVE-2007-5461Apache Tomcat WebDav远程信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2007-5460

No comments yet


Leave a comment