CVE Vulnerabilities

CVE-2002-2438

Improper Authentication

Published: May 18, 2021 | Modified: Nov 20, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*2.4.20 (excluding)
LinuxUbuntuupstream*
Linux-fsl-imx51Ubuntulucid*
Linux-linaro-omapUbuntudevel*
Linux-linaro-omapUbuntunatty*
Linux-linaro-omapUbuntuoneiric*
Linux-linaro-omapUbuntuprecise*
Linux-linaro-sharedUbuntudevel*
Linux-linaro-sharedUbuntuoneiric*
Linux-linaro-sharedUbuntuprecise*
Linux-linaro-vexpressUbuntudevel*
Linux-linaro-vexpressUbuntunatty*
Linux-linaro-vexpressUbuntuoneiric*
Linux-linaro-vexpressUbuntuprecise*
Linux-lts-backport-maverickUbuntulucid*
Linux-mvl-doveUbuntulucid*
Linux-qcm-msmUbuntudevel*
Linux-qcm-msmUbuntulucid*
Linux-qcm-msmUbuntunatty*
Linux-qcm-msmUbuntuoneiric*
Linux-qcm-msmUbuntuprecise*

Potential Mitigations

References