« Volver al listado

CVE-2003-0773

Estado: ModificadaAlta (7.5)—

saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-0773",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2003-09-22T04:00:00.000",
  "references": [
    {
      "url": "ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2003/dsa-379",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2003:099",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2003_046_sane.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2003-278.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2003-285.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/8593",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/8595",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-005.0/CSSA-2004-005.0.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2003/dsa-379",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2003:099",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2003_046_sane.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2003-278.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2003-285.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/8593",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/8595",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf."
    },
    {
      "lang": "es",
      "value": "saned en sane-backends 1.0.7 y anteriores no verifica la dirección IP de la máquina que se conecta durante una llamada SANE_NET_INIT RPC, lo que permite a usuarios remotos usar ese evento de llamada incluso y están restringidos en saned.conf"
    }
  ],
  "lastModified": "2026-06-16T22:02:48.493",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49B2EFC6-08BE-45A6-81A9-1592C18FC41E"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C653F5D7-8F19-4EA6-A3E1-CBE493D45E86"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67D729AD-29EB-4352-811C-CF4BE2A78699"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5081C505-7F02-450F-AFC0-75BBF21C0BED"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75940BFB-561E-4F68-9301-BB4ACC667E08"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6688485-2120-4660-B9C2-3DFA1BE970AD"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A638B1D-4542-4195-990C-43F451B4A6BA"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F806EB9D-A188-4580-B01E-3EFC5791A771"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.7_beta1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AB22C87-F2E6-493F-AE53-B9549A786372"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.7_beta2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB0E5793-44DB-48F4-B07C-740E45F87A0D"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFE0F785-1D8C-4B58-B437-EA5E71645A04"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane:1.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D360EAE-7D1D-463F-B9F2-CC1C8D0A2819"
            },
            {
              "criteria": "cpe:2.3:a:sane:sane-backend:1.0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E7DF79C-DB91-4625-8F47-E18E828D5F81"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}