SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2003-1379

clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the…

MEDIUM 5.0EPSS 1.89%

Does this matter?

Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.

Description

clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.89% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
point clark networks/clarkconnect
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.