VulnerabilityModified
CVE-2002-0592
AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user.
HIGH 7.5EPSS 1.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- aol/instant messenger
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/269006Vendor Advisory
- http://www.securityfocus.com/bid/4574Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8931
- http://online.securityfocus.com/archive/1/269006Vendor Advisory
- http://www.securityfocus.com/bid/4574Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8931
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.