HIGH · 10.0

CVE-2000-1209

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products ...

Vulnerability Description

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CompaqInsight Manager7.0
CompaqInsight Manager Xe1.1
MicrosoftData Engine1.0
MicrosoftMsde2000

References

FAQ

What is CVE-2000-1209?

CVE-2000-1209 is a vulnerability with a CVSS score of 10.0 (HIGH). The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products ...

How severe is CVE-2000-1209?

CVE-2000-1209 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2000-1209?

Check the references section above for vendor advisories and patch information. Affected products include: Compaq Insight Manager, Compaq Insight Manager Xe, Microsoft Data Engine, Microsoft Msde.