CVE-2002-2036: High severity Sun Ray Server Software vulnerability
Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable Non-Smartcard Mobility (NSCM) in SRSS 1.3 configuration to prevent remote logins via dtlogin/XDMCP when NSCM is enabled.
Sun Ray Server Software (SRSS) 1.3 Non-Smartcard Mobility (NSCM) = disabled - Compensating control
Block or restrict access from XDMCP clients to Sun Ray Server Software (SRSS) instances (e.g., via network firewall or ACLs) to prevent dtlogin-based remote login attempts.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2036?
CVE-2002-2036 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized access to user accounts.
How do I fix CVE-2002-2036?
To fix CVE-2002-2036, disable Non-Smartcard Mobility (NSCM) in the Sun Ray Server Software configuration.
Who is affected by CVE-2002-2036?
CVE-2002-2036 affects installations of Sun Ray Server Software version 1.3 when NSCM is enabled.
What type of attack is possible with CVE-2002-2036?
CVE-2002-2036 allows remote attackers to impersonate other users by exploiting the dtlogin via an XDMCP client.
When was CVE-2002-2036 reported?
CVE-2002-2036 was reported in the year 2002, highlighting long-standing vulnerability issues in the Sun Ray Server Software.