CVE-2003-0174
CRITICALCVSS 9.8/10EPSS 0.98%
Last modified
CVE-2003-0174 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sgi | Irix | <= 6.5.19 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20030407-01-PBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7442Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11860Third Party Advisory, VDB Entry
- ftp://patches.sgi.com/support/free/security/advisories/20030407-01-PBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/7442Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11860Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0174?
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
How severe is CVE-2003-0174?
CVE-2003-0174 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.98% probability of exploitation in the next 30 days.
How do I fix CVE-2003-0174?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0168Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Wi…
- CVE-2003-0169hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTo…
- CVE-2003-0170Unknown vulnerability in ftpd in IBM AIX 5.2, when configure…
- CVE-2003-0171DirectoryServices in MacOS X trusts the PATH environment var…
- CVE-2003-0172Buffer overflow in openlog function for PHP 4.3.1 on Windows…
- CVE-2003-0173xfsdq in xfsdump does not create quota information files sec…
- CVE-2003-0175SGI IRIX before 6.5.21 allows local users to cause a denial …
- CVE-2003-0176The Name Service Daemon (nsd), when running on an NIS master…
- CVE-2003-0177SGI IRIX 6.5.x through 6.5.20f, and possibly earlier version…
- CVE-2003-0178Multiple buffer overflows in Lotus Domino Web Server before …
- CVE-2003-0179Buffer overflow in the COM Object Control Handler for Lotus …
- CVE-2003-0180Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remo…
Are you affected by CVE-2003-0174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
