CVE-2000-0969
Estado: ModificadaAlta (10)—
Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.48%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html
- http://www.osvdb.org/6983
- http://www.securityfocus.com/archive/1/141060
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5413
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html
- http://www.osvdb.org/6983
- http://www.securityfocus.com/archive/1/141060
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5413
JSON original (NVD)
Mostrar
{
"id": "CVE-2000-0969",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2000-12-19T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/6983",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/141060",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/5413",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/6983",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/141060",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/5413",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon."
},
{
"lang": "es",
"value": "Vulnerabilidad de cadena de formato en el servidor dedicado de Half Life build 3104 y anteriores permite a atacantes remotos ejecutar comandos arbitrarios inyectando cadenas de formato en el comando changelevel, a través de la consola del sistema o rcon."
}
],
"lastModified": "2026-09-23T09:10:01.707",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:valve_software:half-life_dedicated_server:3.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CA42F82-2F19-4253-B9B2-AED23607672E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}