Vulnerability Details CVE-2002-1872
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2002-1872
-
cpe:2.3:a:microsoft:sql_server:2000
-
cpe:2.3:a:microsoft:sql_server:6.0
-
cpe:2.3:a:microsoft:sql_server:6.5
-
cpe:2.3:a:microsoft:sql_server:7.0