CVE-2010-0833
Last modified
CVE-2010-0833 is a vulnerability of currently unknown severity. The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.. EPSS estimates a 4.14% chance of exploitation in the next 30 days.
Description
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Likewise | Likewise Open | 5.4 |
| Likewise | Likewise Open | 6.0 |
| Likewise | Likewise Cifs | 5.4 |
References
- http://secunia.com/advisories/40725Vendor Advisory
- http://secunia.com/advisories/40736Vendor Advisory
- http://secunia.com/advisories/43244Vendor Advisory
- http://www.likewise.com/community/index.php/forums/viewthread/772/Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1913Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0312Vendor Advisory
- http://secunia.com/advisories/40725Vendor Advisory
- http://secunia.com/advisories/40736Vendor Advisory
- http://secunia.com/advisories/43244Vendor Advisory
- http://www.likewise.com/community/index.php/forums/viewthread/772/Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1913Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0312Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0833?
How severe is CVE-2010-0833?
How do I fix CVE-2010-0833?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-0827Integer overflow in dvips in TeX Live 2009 and earlier, and …
- CVE-2010-0828Cross-site scripting (XSS) vulnerability in action/Despam.py…
- CVE-2010-0829Multiple array index errors in set.c in dvipng 1.11 and 1.12…
- CVE-2010-0830Integer signedness error in the elf_get_dynamic_info functio…
- CVE-2010-0831Directory traversal vulnerability in the extract_jar functio…
- CVE-2010-0832pam_motd (aka the MOTD module) in libpam-modules before 1.1.…
- CVE-2010-0834The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 …
- CVE-2010-0835Unspecified vulnerability in the Wireless component in Oracl…
- CVE-2010-0836Unspecified vulnerability in the Oracle Knowledge Management…
- CVE-2010-0837Unspecified vulnerability in the Pack200 component in Oracle…
- CVE-2010-0838Unspecified vulnerability in the Java 2D component in Oracle…
- CVE-2010-0839Unspecified vulnerability in the Sound component in Oracle J…
Are you affected by CVE-2010-0833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
