CVE-2003-0670 describes a vulnerability in Sustworks IPNetSentryX and IPNetMonitorX where local users can sniff network packets. This is possible due to setuid helper applications, RunTCPDump and RunTCPFlow, which invoke tcpdump and tcpflow respectively. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating a local attack vector with low complexity, resulting in potential confidentiality impact but no integrity or availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not on the KEV or Hot List, though it has received a notable amount of community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:sustainable_softworks:ipnetmonitorx:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:sustainable_softworks:ipnetsentryx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.