Vulnerability Name: | CVE-2003-0724 |
Assigned: | 2003-10-20 |
Published: | 2003-10-20 |
Updated: | 2008-09-05 |
Summary: | ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.
|
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | ALLOWS_OTHER_ACCESS |
References: | Source: MITRE Type: CNA CVE-2003-0724
Source: HP Type: Vendor Advisory SSRT3588
Source: BID Type: Patch, Vendor Advisory 8492
|
Vulnerable Configuration: | Configuration 1: cpe:/o:compaq:tru64:5.1a:*:*:*:*:*:*:*OR cpe:/o:compaq:tru64:5.1a_pk1_bl1:*:*:*:*:*:*:*OR cpe:/o:compaq:tru64:5.1a_pk2_bl2:*:*:*:*:*:*:*OR cpe:/o:compaq:tru64:5.1a_pk3_bl3:*:*:*:*:*:*:*OR cpe:/o:compaq:tru64:5.1a_pk4_bl21:*:*:*:*:*:*:*OR cpe:/o:compaq:tru64:5.1a_pk5_bl23:*:*:*:*:*:*:*OR cpe:/o:compaq:tru64:5.1b_pk2_bl22:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |