SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0994

SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.

HIGH 7.5EPSS 2.89%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.89% probability · 86th percentile
CISA KEV
Not listed
Affected
sun/sun pci ii driver
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.