Описание
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
Ссылки
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Broken Link
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Broken Link
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:microsoft:sql_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:6.5:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp2:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:7.0:sp4:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2000:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2000:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:sql_server:2000:sp2:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01171
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-326
Связанные уязвимости
CVSS3: 7.5
github
почти 4 года назад
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
EPSS
Процентиль: 78%
0.01171
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-326