CVE-2002-2280 describes a vulnerability in syslogd on OpenBSD versions 2.9 through 3.2 where the source IP address of syslog packets is not updated after a network interface configuration change, leading to incorrect information being sent to syslog servers. This vulnerability has a low CVSS score of 2.1, indicating local access is required with no authentication, and primarily impacts data integrity by sending inaccurate source IP information. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9CPE matchmatch criteria | cpe:2.3:o:openbsd:openbsd:2.9:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:openbsd:openbsd:3.0:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:o:openbsd:openbsd:3.1:*:*:*:*:*:*:* | ||
3.2CPE matchmatch criteria | cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.