SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-1151

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation…

MEDIUM 6.8EPSS 3.77%

Does this matter?

Lower severity and a low EPSS score (3.77%). Track it; it rarely justifies an emergency change on its own.

Description

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.77% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
apache/apache http server
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.