VulnerabilityModified
CVE-2002-1869
Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event…
LOW 3.3EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-667
- Affected
- heysoft/eventsave · heysoft/eventsave\+
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1005517Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.heysoft.de/nt/eventlog/hsb01e.htmBroken Link, Patch
- http://www.iss.net/security_center/static/10535.phpBroken Link, Patch
- http://www.securityfocus.com/bid/6095Broken Link, Patch, Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1005517Broken Link, Patch, Third Party Advisory, VDB Entry
- http://www.heysoft.de/nt/eventlog/hsb01e.htmBroken Link, Patch
- http://www.iss.net/security_center/static/10535.phpBroken Link, Patch
- http://www.securityfocus.com/bid/6095Broken Link, Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.