CVE-2002-1689
published 2002-12-31CVE-2002-1689: Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which…
PriorityP263critical10CVSS 2.0
AVNACLAuNCCICAC
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.10%
79.6th percentile
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor login attempts supplying 100 or more environment variables, which may indicate exploitation of the buffer overflow in the login program. ↗
- →Alert on or block remote interactive login sessions to /bin/login from untrusted hosts, as exploitation is delivered via remote login services. ↗
- ·All Cisco products and applications installed on Solaris OS are considered vulnerable unless access services such as /bin/login have been explicitly disabled. ↗
- ·The vulnerability is in the underlying Solaris OS /bin/login program, not in the Cisco product or application itself; patching the OS is required. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xqmh-wj7x-9rxf: Unknown vulnerability in the login program on AIX before 4
ghsa_unreviewed·2022-04-30
CVE-2002-1689 [HIGH] GHSA-xqmh-wj7x-9rxf: Unknown vulnerability in the login program on AIX before 4
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
VulnCheck
AIX before 4.0 Buffer Overflow
vulncheck·2002·CVSS 10.0
CVE-2002-1689 [CRITICAL] AIX before 4.0 Buffer Overflow
AIX before 4.0 Buffer Overflow
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
Affected: IBM aix
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=a9c54f79-d780-437b-a7f5-a74960e299d5&CommunityKey=8af7f28f-02f1-4107-8639-93a60b6546d4&tab=librarydocuments
Cisco
Solaris /bin/login Vulnerability
vendor_cisco·2002-04-10
CVE-2001-0797 CWE-119 Solaris /bin/login Vulnerability
Solaris /bin/login Vulnerability
This advisory describes a vulnerability that affects Cisco products and
applications that are installed on the Solaris operating system, and is based
on the vulnerability of an common service within the Solaris operating system,
not due to a defect of the Cisco product or application. A vulnerability in the
"/bin/login" program was discovered that enables an attacker to execute
arbitrary code under Solaris OS. This vulnerability was discovered and publicly
announced by Internet Security Systems Inc. All Cisco products and applications
that are installed on Solaris OS are considered vulnerable to the underlying
operating system vulnerability, unless steps have been taken to disable access
services such as "bin/login."
We are investigating other Solaris-base
Cisco
Solaris /bin/login Vulnerability
vendor_cisco
CVE-2002-1689 Solaris /bin/login Vulnerability
CVE-2002-1689: Solaris /bin/login Vulnerability
This advisory describes a vulnerability that affects Cisco products and applications that are installed on the Solaris operating system, and is based on the vulnerability of an common service within the Solaris operating system, not due to a defect of the Cisco product or application. A vulnerability in the "/bin/login" program was discovered that enables an attacker to execute arbitrary code under Solaris OS. This vulnerability was discovered and publicly announced by Internet Security Systems Inc. All Cisco products and applications that are installed on Solaris OS are considered vulnerable to the underlying operating system vulnerability, unless steps have been taken to disable access services such as "bin/login." We are investigating othe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2002-12-31
Published
Exploited in the wild