关键漏洞信息 CVE ID: CVE-2012-5320 CVSS 2.0 Base Score: 4.3 Description: - Summary: The Sagem F@ST 2604 253180972B device has a security vulnerability: an attacker can send a malformed HTTP request to modify the admin password. - Possible Checks: Cross-site scripting, Web cache poisoning, and other malicious activities. - Consequences: Gain Access CVSS Metrics: - Access Vector: Network - Access Complexity: Medium - Authentication: None - Confidentiality Impact: None - Integrity Impact: Partial - Availability Impact: None Temporal Score: 4.1 - Exploitability: High - Remediation Level: Unavailable - Report Confidence: Uncorrelated Remedy: No remedy available as of October 1, 2014. Affected Products: Sagem F@st 2604 253180972B. References: - Offensive Security Exploit Database [02-22-2012] - Sagem Telecommunications Web site - SA48088 - OSVDB ID: 79649