CVE-2002-1227PAM vulnerability

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.7%
top 27.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateApr 30

Description

PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/pam< pam 0.76-6 (bookworm)
Debianpam/pam< 0.76-6+3
NVDpam/pam0.76

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pw86-jwrv-pxmm: PAM 02022-04-30
OSV
CVE-2002-1227: PAM 02002-10-28

📋Vendor Advisories

1
Debian
CVE-2002-1227: pam - PAM 0.76 treats a disabled password as if it were an empty (null) password, whic...2002
CVE-2002-1227 — Debian PAM vulnerability | cvebase