Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2002-0054


SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.


Published

2002-03-08T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-294

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft exchange_server 5.5 Yes
Application microsoft exchange_server 5.5 Yes
Application microsoft exchange_server 5.5 Yes
Application microsoft exchange_server 5.5 Yes
Application microsoft exchange_server 5.5 Yes
Operating System microsoft windows_2000 - Yes
Operating System microsoft windows_2000 - Yes
Operating System microsoft windows_2000 - Yes

References