CVE-2002-2162 describes a vulnerability in Cerulean Studios Trillian 0.73 and earlier, where user passwords stored in .ini files are protected only by weak XOR encryption. This allows local attackers to easily decrypt and access other user accounts. The vulnerability has a CVSS score of 4.6, indicating a low attack complexity but requiring local access to achieve partial confidentiality, integrity, and availability impact. While no active exploitation is reported and community discussion is minimal, an exploit demonstrating credential encryption bypass is available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.73CPE matchmatch criteria | cpe:2.3:a:cerulean_studios:trillian:0.73:*:*:*:*:*:*:* | ||
0.725CPE matchmatch criteria | cpe:2.3:a:cerulean_studios:trillian:0.725:*:*:*:*:*:*:* | ||
0.6351CPE matchmatch criteria | cpe:2.3:a:cerulean_studios:trillian:0.6351:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.