CVE-2002-0674
Estado: ModificadaAlta (7.2)—
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://www.atstake.com/research/advisories/2002/a071202-1.txt
- http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp
- http://www.securityfocus.com/bid/5221
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9569
- http://www.atstake.com/research/advisories/2002/a071202-1.txt
- http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp
- http://www.securityfocus.com/bid/5221
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9569
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0674",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-07-23T04:00:00.000",
"references": [
{
"url": "http://www.atstake.com/research/advisories/2002/a071202-1.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5221",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/9569",
"source": "cve@mitre.org"
},
{
"url": "http://www.atstake.com/research/advisories/2002/a071202-1.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/5221",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/9569",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not \"time out\" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication."
},
{
"lang": "es",
"value": "La telefonía basada en voz sobre IP de Pingtel xpressa SIP desde la versión 1.2.5 hasta la 1.2.7.4, no posee 'tiempo máximo de espera' (time out) en las sesiones inactivas de administrador, lo cula podría permitir a otros usuarios realizar tareas de administrador si tal administrador no explicita el fin de su sesión."
}
],
"lastModified": "2026-06-16T21:57:55.180",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5362ACDC-DA8B-4DA7-BEE3-C30083CD715D"
},
{
"criteria": "cpe:2.3:h:pingtel:xpressa:1.2.7.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F08D9EF-49D8-44CC-B33D-4EF416E80F62"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}