CVE-2002-0480
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- iss/realsecure nokia
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101666833321138&w=2
- http://marc.info/?l=bugtraq&m=101675086010051&w=2
- http://marc.info/?l=bugtraq&m=101684141308876&w=2
- http://www.securityfocus.com/bid/4331
- http://marc.info/?l=bugtraq&m=101666833321138&w=2
- http://marc.info/?l=bugtraq&m=101675086010051&w=2
- http://marc.info/?l=bugtraq&m=101684141308876&w=2
- http://www.securityfocus.com/bid/4331
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.