CVE-2002-0236: High severity Lucent VitalEvent vulnerability
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0236?
CVE-2002-0236 is classified as a high severity vulnerability due to the potential for remote attackers to bypass authentication.
How do I fix CVE-2002-0236?
To fix CVE-2002-0236, ensure that you apply the latest patches provided by Lucent for all affected versions of the VitalSuite software.
Which versions of Lucent software are affected by CVE-2002-0236?
CVE-2002-0236 affects Lucent VitalSuite versions 8.0 to 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis.
Can CVE-2002-0236 be exploited without authentication?
Yes, CVE-2002-0236 can be exploited without authentication through a direct HTTP request.
What components of Lucent software are impacted by CVE-2002-0236?
CVE-2002-0236 impacts multiple components such as VitalNet, VitalEvent, and VitalHelp/VitalAnalysis within the Lucent VitalSuite.