« Back to list

CVE-2000-0572

Status: ModifiedMedium (4.6)—💥 Exploit

The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2000-0572",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2000-07-05T04:00:00.000",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/1424",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-07-8&msg=613309F30B6DD2118C020000F809376C05CABD49%40emss03m09.orl.lmco.com",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/1424",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-07-8&msg=613309F30B6DD2118C020000F809376C05CABD49%40emss03m09.orl.lmco.com",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges."
    }
  ],
  "lastModified": "2026-06-16T21:52:01.463",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:visible_systems:razor:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D706F22A-65ED-4893-B4B3-2594316F18B2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Subsequent releases of Razor address this issue and utilize a more robust encryption mechanism for the Razor password. If you are under maintenance, you have the option of upgrading to a more recent release of Razor at no cost.  If you are not under maintenance and want to upgrade then you will need to contact Jennifer Stone at jstone@visible.com.\n\nSome additional notes ...\n\n- With version 4.1 and above, administrators of Razor may switch and use the local OS authentication instead of Razor’s authentication method.\n\n- OS permissions and protections always apply to the artifacts stored in the database.\n\n- This notice applies to users that have already logged into the supporting system.  This primary means of defense is intact inspite of this particular vulnerability.\n\n- The next Razor release (due out in mid-2007) will allow remote UNIX clients to utilize SSH to authenticate the remote user.  More information on this release and others may be found on the Visible Systems web site:\n\nhttp://www.visible.com/Products/Razor\n\nPlease contact Visible Systems Corporation at 1-800-6-VISIBLE if you have additional questions.",
      "lastModified": "2007-02-22T00:00:00",
      "organization": "Razor"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}