First published: Thu Jul 12 2007(Updated: )
The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 does not log the source IP address or attempted username for login attempts, which might help remote attackers to avoid identification.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVMS | =8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3730 has a moderate severity level due to the lack of logging for source IP addresses and usernames, which can hinder incident response.
To fix CVE-2007-3730, configure the POP server to enable logging of source IP addresses and attempted usernames.
CVE-2007-3730 affects the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3.
The primary risk of CVE-2007-3730 is that attackers may carry out unauthorized login attempts without leaving traceable activity.
Yes, CVE-2007-3730 is considered exploitable remotely since it involves the configuration of a network service.