First published: Tue Jun 11 2002(Updated: )
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISS RealSecure | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0480 is considered to have a high severity due to the potential for unauthorized access and manipulation of security settings.
To fix CVE-2002-0480, upgrade ISS RealSecure to the latest version where this vulnerability has been patched.
CVE-2002-0480 affects ISS RealSecure for Nokia devices running versions before IPSO build 6.0.2001.141d.
The potential impacts of CVE-2002-0480 include unauthorized key management and possible exploitation by remote attackers.
While CVE-2002-0480 was reported over two decades ago, it remains a concern for any unpatched systems still in use.