CVE-2010-1040
Summary
| CVE | CVE-2010-1040 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-23 18:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tejimaya | Openpne | 1.6 | All | All | All |
| Application | Tejimaya | Openpne | 1.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.10 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.11 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.12 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.13 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.13.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.4.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.4.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.5.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.7 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.10.9 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.3.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.5.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.11.7 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.10 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.11 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.12 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.13 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.14 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.14.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.15 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.16 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.17 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.17.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.18 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.7 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.12.9 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.7 | All | All | All |
| Application | Tejimaya | Openpne | 2.13.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.14.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.3.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.3.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.3.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.3.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.7 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.4.8.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.5.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.10 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.11.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.5 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.6 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.6.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.6.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.7 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.8 | All | All | All |
| Application | Tejimaya | Openpne | 2.6.9 | All | All | All |
| Application | Tejimaya | Openpne | 2.7.0 | All | All | All |
| Application | Tejimaya | Openpne | 2.7.1 | All | All | All |
| Application | Tejimaya | Openpne | 2.7.2 | All | All | All |
| Application | Tejimaya | Openpne | 2.7.3 | All | All | All |
| Application | Tejimaya | Openpne | 2.7.4 | All | All | All |
| Application | Tejimaya | Openpne | 2.8.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#06874657 OpenPNE authentication bypass vulnerability | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| OpenPNE Security Bypass Security Issue - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 【緊急リリース】携帯版かんたんログインの不備によりなりすましがおこなわれてしまう問題について|OpenPNE | af854a3a-2127-422b-91ae-364da2661108 | www.openpne.jp | Vendor Advisory |
| jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000006.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| 脆弱性対策 : 「OpenPNE」におけるセキュリティ上の弱点(脆弱性)の注意喚起:IPA 独立行政法人 情報処理推進機構 | af854a3a-2127-422b-91ae-364da2661108 | www.ipa.go.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.