Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-0862 | First vendor Publication | 2002-10-04 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0862 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-295 | Certificate Issues |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:1056 | |||
Oval ID: | oval:org.mitre.oval:def:1056 | ||
Title: | Microsoft Certificate Validation Flaw Identity Spoofing Vulnerability | ||
Description: | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-0862 | Version: | 8 |
Platform(s): | Microsoft Windows XP | Product(s): | Microsoft CryptoAPI |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:1332 | |||
Oval ID: | oval:org.mitre.oval:def:1332 | ||
Title: | Windows 2000 Certificate Validation Identity Spoofing Vulnerability (Test 1) | ||
Description: | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-0862 | Version: | 8 |
Platform(s): | Microsoft Windows 2000 | Product(s): | Certificate Validation |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:2671 | |||
Oval ID: | oval:org.mitre.oval:def:2671 | ||
Title: | Windows 2000 Certificate Validation Identity Spoofing Vulnerability (Test 2) | ||
Description: | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-0862 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 | Product(s): | Certificate Validation |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 1 | |
Os | 1 | |
Os | 1 | |
Os | 2 | |
Os | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-03-16 | Name : Microsoft MS03-018 security check File : nvt/remote-MS03-018.nasl |
2009-03-15 | Name : MS04-011 security check File : nvt/remote-MS04-011.nasl |
2005-11-03 | Name : Certificate Validation Flaw Could Enable Identity Spoofing (Q328145) File : nvt/smb_nt_ms02-050.nasl |
2005-11-03 | Name : Flaw in Microsoft VM Could Allow Code Execution (810030) File : nvt/smb_nt_ms02-052.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
865 | Multiple Vendor SSL Basic Constraints Intermediate CA-signed Certificate Vali... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2002-10-24 | Name : It is possible to spoof user identities. File : smb_nt_ms02-050.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:46 |
|
2024-11-28 12:05:07 |
|
2024-02-09 09:28:01 |
|
2024-02-02 01:02:02 |
|
2024-02-01 12:01:22 |
|
2023-09-05 12:01:56 |
|
2023-09-05 01:01:13 |
|
2023-09-02 12:01:57 |
|
2023-09-02 01:01:13 |
|
2023-08-12 12:02:19 |
|
2023-08-12 01:01:13 |
|
2023-08-11 12:02:02 |
|
2023-08-11 01:01:15 |
|
2023-08-06 12:01:52 |
|
2023-08-06 01:01:14 |
|
2023-08-04 12:01:56 |
|
2023-08-04 01:01:14 |
|
2023-07-14 12:01:54 |
|
2023-07-14 01:01:14 |
|
2023-03-29 01:01:53 |
|
2023-03-28 12:01:19 |
|
2022-10-11 12:01:42 |
|
2022-10-11 01:01:07 |
|
2021-07-27 00:24:38 |
|
2021-07-24 01:44:15 |
|
2021-07-24 01:01:23 |
|
2021-07-23 17:24:42 |
|
2021-07-23 01:44:03 |
|
2021-07-23 01:01:22 |
|
2021-07-22 21:24:59 |
|
2021-05-04 12:01:43 |
|
2021-04-22 01:01:51 |
|
2020-05-23 00:15:02 |
|
2019-05-09 12:01:12 |
|
2019-04-30 21:19:17 |
|
2018-10-31 00:19:41 |
|
2018-10-13 00:22:25 |
|
2017-10-11 09:23:15 |
|
2017-07-11 12:01:10 |
|
2016-10-18 12:01:02 |
|
2016-08-31 12:00:42 |
|
2016-06-28 14:59:33 |
|
2016-04-26 12:13:14 |
|
2014-02-17 10:24:55 |
|
2013-05-11 12:10:50 |
|