CVE-2002-0570
UnknownEPSS 0.40%
Last modified
CVE-2002-0570 is a vulnerability of currently unknown severity. The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.2.0 |
| Linux | Linux Kernel | 2.2.1 |
| Linux | Linux Kernel | 2.2.2 |
| Linux | Linux Kernel | 2.2.3 |
| Linux | Linux Kernel | 2.2.4 |
| Linux | Linux Kernel | 2.2.5 |
| Linux | Linux Kernel | 2.2.6 |
| Linux | Linux Kernel | 2.2.7 |
| Linux | Linux Kernel | 2.2.8 |
| Linux | Linux Kernel | 2.2.9 |
| Linux | Linux Kernel | 2.2.10 |
| Linux | Linux Kernel | 2.2.11 |
| Linux | Linux Kernel | 2.2.12 |
| Linux | Linux Kernel | 2.2.13 |
| Linux | Linux Kernel | 2.2.14 |
| Linux | Linux Kernel | 2.2.15 |
| Linux | Linux Kernel | 2.2.16 |
| Linux | Linux Kernel | 2.2.17 |
| Linux | Linux Kernel | 2.2.18 |
| Linux | Linux Kernel | 2.2.19 |
| Linux | Linux Kernel | 2.2.20 |
| Linux | Linux Kernel | 2.4.0 |
| Linux | Linux Kernel | 2.4.1 |
| Linux | Linux Kernel | 2.4.2 |
| Linux | Linux Kernel | 2.4.3 |
| Linux | Linux Kernel | 2.4.4 |
| Linux | Linux Kernel | 2.4.5 |
| Linux | Linux Kernel | 2.4.6 |
| Linux | Linux Kernel | 2.4.7 |
| Linux | Linux Kernel | 2.4.8 |
| Linux | Linux Kernel | 2.4.9 |
| Linux | Linux Kernel | 2.4.10 |
| Linux | Linux Kernel | 2.4.11 |
| Linux | Linux Kernel | 2.4.12 |
| Linux | Linux Kernel | 2.4.13 |
| Linux | Linux Kernel | 2.4.14 |
| Linux | Linux Kernel | 2.4.15 |
| Linux | Linux Kernel | 2.4.16 |
| Linux | Linux Kernel | 2.4.17 |
References
- http://www.securityfocus.com/bid/3775Vendor Advisory
- http://www.securityfocus.com/bid/3775Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0570?
The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.
How severe is CVE-2002-0570?
Severity scoring for CVE-2002-0570 is pending analysis. The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0570?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0564PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.…
- CVE-2002-0565Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directo…
- CVE-2002-0566PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.…
- CVE-2002-0567Oracle 8i and 9i with PL/SQL package for External Procedures…
- CVE-2002-0568Oracle 9i Application Server stores XSQL and SOAP configurat…
- CVE-2002-0569Oracle 9i Application Server allows remote attackers to bypa…
- CVE-2002-0571Oracle Oracle9i database server 9.0.1.x allows local users t…
- CVE-2002-0572FreeBSD 4.5 and earlier, and possibly other BSD-based operat…
- CVE-2002-0573Format string vulnerability in RPC wall daemon (rpc.rwalld) …
- CVE-2002-0574Memory leak in FreeBSD 4.5 and earlier allows remote attacke…
- CVE-2002-0575Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.…
- CVE-2002-0576ColdFusion 5.0 and earlier on Windows systems allows remote …
Are you affected by CVE-2002-0570?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
