CVE Vulnerabilities

CVE-2002-0236

Published: May 29, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.

Affected Software

NameVendorStart VersionEnd Version
VitalanalysisLucent8.0 (including)8.0 (including)
VitalanalysisLucent8.1 (including)8.1 (including)
VitalanalysisLucent8.2 (including)8.2 (including)
VitaleventLucent8.0 (including)8.0 (including)
VitaleventLucent8.1 (including)8.1 (including)
VitaleventLucent8.2 (including)8.2 (including)
VitalhelpLucent8.0 (including)8.0 (including)
VitalhelpLucent8.1 (including)8.1 (including)
VitalhelpLucent8.2 (including)8.2 (including)
VitalnetLucent8.0 (including)8.0 (including)
VitalnetLucent8.1 (including)8.1 (including)
VitalnetLucent8.2 (including)8.2 (including)
VitalsuiteLucent8.0 (including)8.0 (including)
VitalsuiteLucent8.1 (including)8.1 (including)
VitalsuiteLucent8.2 (including)8.2 (including)

References