{"api_version":"1","generated_at":"2026-07-23T04:28:49+00:00","cve":"CVE-2007-0655","urls":{"html":"https://cve.report/CVE-2007-0655","api":"https://cve.report/api/cve/CVE-2007-0655.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0655","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0655"},"summary":{"title":"CVE-2007-0655","description":"The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.","state":"PUBLISHED","assigner":"flexera","published_at":"2007-05-02 18:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/secunia_research/2007-45/advisory/","name":"http://secunia.com/secunia_research/2007-45/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"eScan Products Agent Service Missing User Authentication - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23759","name":"http://www.securityfocus.com/bid/23759","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EScan Product Agent Service MWAGENT.EXE Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/1609","name":"http://www.vupen.com/english/advisories/2007/1609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/35732","name":"http://osvdb.org/35732","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34009","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34009","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23809","name":"http://secunia.com/advisories/23809","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"eScan Products Agent Service Missing User Authentication - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018007","name":"http://www.securitytracker.com/id?1018007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"eScan Lack of Authentication Lets Local Users Execute Arbitrary Commands With System Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0655","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0655","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"655","vulnerable":"1","versionEndIncluding":"8.0671.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microworld_technologies","cpe5":"escan","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:26:54.302Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"escan-mwagent-security-bypass(34009)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34009"},{"name":"ADV-2007-1609","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1609"},{"name":"23759","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23759"},{"name":"35732","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35732"},{"name":"23809","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23809"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2007-45/advisory/"},{"name":"1018007","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018007"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"escan-mwagent-security-bypass(34009)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34009"},{"name":"ADV-2007-1609","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1609"},{"name":"23759","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23759"},{"name":"35732","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35732"},{"name":"23809","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23809"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2007-45/advisory/"},{"name":"1018007","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018007"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2007-0655","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"escan-mwagent-security-bypass(34009)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34009"},{"name":"ADV-2007-1609","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1609"},{"name":"23759","refsource":"BID","url":"http://www.securityfocus.com/bid/23759"},{"name":"35732","refsource":"OSVDB","url":"http://osvdb.org/35732"},{"name":"23809","refsource":"SECUNIA","url":"http://secunia.com/advisories/23809"},{"name":"http://secunia.com/secunia_research/2007-45/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2007-45/advisory/"},{"name":"1018007","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018007"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2007-0655","datePublished":"2007-05-02T18:00:00.000Z","dateReserved":"2007-02-01T00:00:00.000Z","dateUpdated":"2024-08-07T12:26:54.302Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-05-02 18:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microworld_technologies:escan:*:*:*:*:*:*:*:*","versionEndIncluding":"8.0671.1","matchCriteriaId":"C09FAEE4-72BD-4C55-B8F7-DB7851B86F59"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"655","Ordinal":"1","Title":"CVE-2007-0655","CVE":"CVE-2007-0655","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"655","Ordinal":"1","NoteData":"The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.","Type":"Description","Title":"CVE-2007-0655"},{"CveYear":"2007","CveId":"655","Ordinal":"2","NoteData":"2007-05-02","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"655","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}