CVE-2002-0888
UnknownEPSS 1.58%
Last modified
CVE-2002-0888 is a vulnerability of currently unknown severity. 3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connecting to an approved port and quickly connecting to the desired port, which is allowed by the router.. EPSS estimates a 1.58% chance of exploitation in the next 30 days.
Description
3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connecting to an approved port and quickly connecting to the desired port, which is allowed by the router.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| 3com | 3cp4144 | 1.1.7 |
| 3com | 3cp4144 | 1.1.9 |
References
- http://www.iss.net/security_center/static/9185.phpVendor Advisory
- http://www.securityfocus.com/bid/4841Patch, Vendor Advisory
- http://www.iss.net/security_center/static/9185.phpVendor Advisory
- http://www.securityfocus.com/bid/4841Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0888?
3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connecting to an approved port and quickly connecting to the desired port, which is allowed by the router.
How severe is CVE-2002-0888?
Severity scoring for CVE-2002-0888 is pending analysis. The EPSS model estimates a 1.58% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0888?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0882The web server for Cisco IP Phone (VoIP) models 7910, 7940, …
- CVE-2002-0883Vulnerability in Compaq ProLiant BL e-Class Integrated Admin…
- CVE-2002-0884Multiple format string vulnerabilities in in.rarpd (ARP serv…
- CVE-2002-0885Multiple buffer overflows in in.rarpd (ARP server) on Solari…
- CVE-2002-0886Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows …
- CVE-2002-0887scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows l…
- CVE-2002-0889Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows…
- CVE-2002-0891The web interface (WebUI) of NetScreen ScreenOS before 2.6.1…
- CVE-2002-0892The default configuration of NewAtlanta ServletExec ISAPI 4.…
- CVE-2002-0893Directory traversal vulnerability in NewAtlanta ServletExec …
- CVE-2002-0894NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to …
- CVE-2002-0895Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remo…
Are you affected by CVE-2002-0888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
