cbcvebase.
CVE-2002-1689
published 2002-12-31

CVE-2002-1689: Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which…

PriorityP263critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.10%
79.6th percentile
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

Affected

1 ranges
VendorProductVersion rangeFixed in
ibmaix

Detection & IOCsextracted from sources · hover to see the quote

path/bin/login
  • Monitor login attempts supplying 100 or more environment variables, which may indicate exploitation of the buffer overflow in the login program.
  • Alert on or block remote interactive login sessions to /bin/login from untrusted hosts, as exploitation is delivered via remote login services.
  • ·All Cisco products and applications installed on Solaris OS are considered vulnerable unless access services such as /bin/login have been explicitly disabled.
  • ·The vulnerability is in the underlying Solaris OS /bin/login program, not in the Cisco product or application itself; patching the OS is required.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.