CVE-2000-0127: High severity Progress WebSpeed vulnerability
The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable access to the WSMadmin utility in the WebSpeed configuration program to prevent remote attackers from gaining privileges via wsisa.dll.
Progress WebSpeed (WSMadmin / wsisa.dll) WSMadmin access = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0127?
CVE-2000-0127 is considered a medium severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2000-0127?
To fix CVE-2000-0127, ensure that access to the WSMadmin utility is properly restricted in the Webspeed configuration.
What software versions are affected by CVE-2000-0127?
CVE-2000-0127 affects Progress Webspeed version 3.0.
What exploit does CVE-2000-0127 enable?
CVE-2000-0127 enables remote attackers to gain unauthorized privileges through the wsisa.dll component.
Is there a known workaround for CVE-2000-0127?
A known workaround for CVE-2000-0127 is to manually disable access to the WSMadmin utility until a patch is applied.