CVE-2002-2108 describes an unspecified vulnerability within the "VAIO Manual" software bundled with certain Sony VAIO personal computers sold between November 2001 and January 2002. This flaw allows remote attackers to modify data through specially crafted web pages or HTML emails. With a CVSS score of 5.0, it is considered a medium-severity vulnerability, requiring no authentication and having low attack complexity, but only impacting data integrity. There is no evidence of active exploitation, nor are there public exploit modules available; however, it has garnered significant community discussion, indicating awareness despite its age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:sony:vaio_manual_cybersupport:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:sony:vaio_manual_cybersupport:3.0:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:sony:vaio_manual_cybersupport:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.