CVE-2002-1872 describes a critical vulnerability in Microsoft SQL Server versions 6.0 through 2000, where SQL Authentication utilizes weak XOR-based password encryption. This flaw allows remote attackers to easily sniff network traffic and decrypt user passwords, compromising database security. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to complete confidentiality compromise. While no active exploitation, public exploit code, or significant community discussion is noted, the fundamental weakness in password handling presents a severe risk if these legacy systems remain in use.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:6.0:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:6.5:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:7.0:sp1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:7.0:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.