Lucene search

K
cve[email protected]CVE-2000-1209
HistoryAug 12, 2002 - 4:00 a.m.

CVE-2000-1209

2002-08-1204:00:00
web.nvd.nist.gov
82
microsoft sql server
null password
remote attack
data engine
privileges
worms
spida
voyager alpha force.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.957 High

EPSS

Percentile

99.4%

The “sa” account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

Affected configurations

NVD
Node
compaqinsight_managerMatch7.0
OR
compaqinsight_managerMatch7.0sp1
OR
compaqinsight_manager_xeMatch1.1
OR
compaqinsight_manager_xeMatch1.21
OR
compaqinsight_manager_xeMatch2.1
OR
compaqinsight_manager_xeMatch2.1b
OR
compaqinsight_manager_xeMatch2.1c
OR
compaqinsight_manager_xeMatch2.2
OR
microsoftdata_engineMatch1.0
OR
microsoftmsdeMatch2000

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.957 High

EPSS

Percentile

99.4%