CVE-2002-0507
Estado: ModificadaBaja (2.1)—
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.22%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0507",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-08-12T04:00:00.000",
"references": [
{
"url": "http://online.securityfocus.com/archive/1/264705",
"tags": [
"Third Party Advisory",
"VDB Entry",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/8681.php",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/4390",
"tags": [
"Third Party Advisory",
"VDB Entry",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://online.securityfocus.com/archive/1/264705",
"tags": [
"Third Party Advisory",
"VDB Entry",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/8681.php",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/4390",
"tags": [
"Third Party Advisory",
"VDB Entry",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA."
},
{
"lang": "es",
"value": "Una interacción entre Microsoft Outlook Web Access (OWA) con RSA SecurID permite a usuarios locales evitar la autenticación SecurID para un usuario anterior mediante varios envios de una petición de autenticación OWA con la contraseña adecuada del usuario anterior, que es acaba siendo aceptada por OWA."
}
],
"lastModified": "2026-06-16T21:57:34.657",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4F9C143-4734-4E5D-9281-F51513C5CAAF"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD3E2F18-A369-4767-ACEF-38DB40EEC6D4"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC01670D-4550-4034-86A5-7879B6334241"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B80A57A1-7B9F-4C07-ADAA-DBC4687F1EFC"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E3983529-F4E3-4883-97AF-5BFC87AC3E86"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2000:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF429469-1B63-4BF3-A59F-F8180226BB6D"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2000:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34300FD4-EC3B-4206-B6C0-1345F17EC5EA"
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2000:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47132D0D-7691-40A3-A4BF-37D2ACE580C3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:rsa:securid:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A00A9D51-90B1-4D58-839F-AD93AD015B80"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}