« Volver al listado

CVE-2002-1520

Estado: ModificadaAlta (10)—

The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-1520",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2003-04-02T05:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0325.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0335.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/10218.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/4831",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/5815",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0325.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2002-09/0335.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/10218.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/4831",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/5815",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges."
    },
    {
      "lang": "es",
      "value": "El interfaz CLI de WatchGuard Firebox Vclass 3.2 y anteriores, y RSSA Appliance 3.0.2 no cierra adecuadamente la conexión SSH cuando se provee una opción -N durante autenticación, lo que permite a atacantes remotos acceder a CLI con privilegios de administrador"
    }
  ],
  "lastModified": "2026-06-16T21:59:28.950",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rapidstream:rapidstream:500:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BEFE717-99B9-4BA1-B221-B35C3B43CDB6"
            },
            {
              "criteria": "cpe:2.3:h:rapidstream:rapidstream:2000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C13F6038-2FB7-4814-A058-D6192963474E"
            },
            {
              "criteria": "cpe:2.3:h:rapidstream:rapidstream:4000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03CD6CE7-23B7-4A45-82C0-A5F10AD9CC55"
            },
            {
              "criteria": "cpe:2.3:h:rapidstream:rapidstream:6000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "653929D6-6E9F-470F-B3DB-95F5E14D2AC0"
            },
            {
              "criteria": "cpe:2.3:h:rapidstream:rapidstream:8000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EFA822E-72CE-4EA6-A7FB-C4FCE94B670D"
            },
            {
              "criteria": "cpe:2.3:h:watchguard:firebox:v10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D7FA2C1-1F55-494A-ADAA-AC5215D211FB"
            },
            {
              "criteria": "cpe:2.3:h:watchguard:firebox:v60:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29973162-719D-47B0-858A-6EC2336967DC"
            },
            {
              "criteria": "cpe:2.3:h:watchguard:firebox:v80:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA50D87E-701F-48CE-81D8-342BC3F19BDA"
            },
            {
              "criteria": "cpe:2.3:h:watchguard:firebox:v100:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29B1E9C2-8336-43BF-A0CC-262A1DC29735"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}