[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2002-2028Date: (C)2002-12-31   (M)2023-12-22


The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
http://cert.uni-stuttgart.de/archive/bugtraq/2002/01/msg00278.html
BID-3933
Q188700
http://www.heysoft.de/nt/lbh.htm

CPE    21
cpe:/o:microsoft:windows_nt:4.0:sp4:server
cpe:/o:microsoft:windows_nt:4.0:sp2:terminal_server
cpe:/o:microsoft:windows_nt:4.0:sp5:server
cpe:/o:microsoft:windows_nt:4.0:sp5:terminal_server
...

© SecPod Technologies