Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-1256 | First vendor Publication | 2002-12-23 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1256 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:277 | |||
Oval ID: | oval:org.mitre.oval:def:277 | ||
Title: | SMB Session Digital Signature Sidestep | ||
Description: | The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-1256 | Version: | 2 |
Platform(s): | Microsoft Windows 2000 | Product(s): | SMB Signing (Server Message Block) |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 4 | |
Os | 4 | |
Os | 3 |
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : Flaw in SMB Signing Could Enable Group Policy to be Modified (329170) File : nvt/smb_nt_ms02-070.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
11799 | Microsoft Windows SMB Signing Group Policy Modification |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2003-01-25 | Name : It is possible to send unsigned SMB packets. File : smb_nt_ms02-070.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:43 |
|
2024-11-28 12:05:13 |
|
2021-05-04 12:01:47 |
|
2021-04-22 01:01:54 |
|
2020-05-23 00:15:07 |
|
2019-04-30 21:19:17 |
|
2018-10-13 00:22:26 |
|
2017-10-10 09:23:25 |
|
2016-08-31 12:00:43 |
|
2016-06-28 15:00:25 |
|
2016-04-26 12:16:58 |
|
2014-02-17 10:25:13 |
|
2013-05-11 12:12:17 |
|