CVE-2002-1872
moderate-risk
Published 2002-12-31
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
Do I need to act?
~
1.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (10)
Affected Vendors
References (8)
Broken Link
http://online.securityfocus.com/archive/1/298361
Broken Link
http://www.nextgenss.com/papers/tp-SQL2000.pdf
Broken Link
http://www.securityfocus.com/bid/6097
Broken Link
http://online.securityfocus.com/archive/1/298361
Broken Link
http://www.nextgenss.com/papers/tp-SQL2000.pdf
Broken Link
http://www.securityfocus.com/bid/6097
45
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
3/34 · Minimal
Exposure
16/34 · Moderate