Vulnerability CVE-2002-0480


Published: 2002-08-12   Modified: 2012-02-12

Description:
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
ISS -> Realsecure nokia 

 References:
http://marc.info/?l=bugtraq&m=101666833321138&w=2
http://marc.info/?l=bugtraq&m=101675086010051&w=2
http://marc.info/?l=bugtraq&m=101684141308876&w=2
http://www.securityfocus.com/bid/4331

Copyright 2024, cxsecurity.com

 

Back to Top