7.5
CVE-2002-1872
- EPSS 1.17%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Sql Server Version6.0
Microsoft ≫ Sql Server Version6.5
Microsoft ≫ Sql Server Version7.0
Microsoft ≫ Sql Server Version7.0 Updatesp1
Microsoft ≫ Sql Server Version7.0 Updatesp2
Microsoft ≫ Sql Server Version7.0 Updatesp3
Microsoft ≫ Sql Server Version7.0 Updatesp4
Microsoft ≫ Sql Server Version2000
Microsoft ≫ Sql Server Version2000 Updatesp1
Microsoft ≫ Sql Server Version2000 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.17% | 0.778 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.