2024-07-14 02:06:08 +00:00

97 lines
2.9 KiB
JSON

{
"id": "CVE-2002-0674",
"sourceIdentifier": "cve@mitre.org",
"published": "2002-07-23T04:00:00.000",
"lastModified": "2017-10-10T01:30:07.093",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not \"time out\" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication."
},
{
"lang": "es",
"value": "La telefon\u00eda basada en voz sobre IP de Pingtel xpressa SIP desde la versi\u00f3n 1.2.5 hasta la 1.2.7.4, no posee 'tiempo m\u00e1ximo de espera' (time out) en las sesiones inactivas de administrador, lo cula podr\u00eda permitir a otros usuarios realizar tareas de administrador si tal administrador no explicita el fin de su sesi\u00f3n."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "5362ACDC-DA8B-4DA7-BEE3-C30083CD715D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:h:pingtel:xpressa:1.2.7.4:*:*:*:*:*:*:*",
"matchCriteriaId": "5F08D9EF-49D8-44CC-B33D-4EF416E80F62"
}
]
}
]
}
],
"references": [
{
"url": "http://www.atstake.com/research/advisories/2002/a071202-1.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5221",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/9569",
"source": "cve@mitre.org"
}
]
}