CVE-2004-0390 describes a vulnerability in SCO OpenServer versions 5.0.5 through 5.0.7 where the Xauthority access control mechanism is only enforced when users log in via scologin. This flaw allows remote attackers to bypass X session access controls by using alternative X login methods. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to unauthorized disclosure, modification, and availability of data. While there is no evidence of active exploitation (KEV: No), an exploit demonstrating weak XHost permissions exists on ExploitDB, and the CVE has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.5CPE matchmatch criteria | cpe:2.3:o:sco:openserver:5.0.5:*:*:*:*:*:*:* | ||
5.0.6CPE matchmatch criteria | cpe:2.3:o:sco:openserver:5.0.6:*:*:*:*:*:*:* | ||
5.0.7CPE matchmatch criteria | cpe:2.3:o:sco:openserver:5.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.