CVE-2002-1947: Medium severity webmin webmin vulnerability
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Generate a unique private key and install a corresponding certificate (self-signed or CA-signed) and configure Webmin to use that key/certificate instead of the default built-in SSL key present in Webmin 0.21 through 1.0.
Webmin SSL private key/certificate = replace built-in key with a unique private key and certificate - Compensating control
Restrict network access to the Webmin management interface to trusted IP addresses or networks using firewall rules or network ACLs to reduce exposure to the shared built-in SSL key (affects Webmin 0.21 through 1.0).
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1947?
CVE-2002-1947 is classified as a high severity vulnerability due to its potential to allow remote attackers to eavesdrop on SSL sessions.
How do I fix CVE-2002-1947?
To fix CVE-2002-1947, upgrade Webmin to a version later than 1.0 that does not use a shared SSL key.
Which versions of Webmin are affected by CVE-2002-1947?
CVE-2002-1947 affects Webmin versions from 0.21 to 1.0, including 0.21, 0.22, 0.31, 0.42, and up to 0.99.
What type of vulnerability is CVE-2002-1947?
CVE-2002-1947 is an SSL session hijacking vulnerability that enables attackers to eavesdrop on encrypted communications.
Is CVE-2002-1947 still a relevant threat?
While CVE-2002-1947 was reported in 2002, its exploitability may still be relevant for systems using outdated versions of Webmin.