Vulnerability Description
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sharp | Zaurus Sl-5000D Firmware | - |
| Sharp | Zaurus Sl-5000D | - |
| Sharp | Zaurus Sl-5500 Firmware | - |
| Sharp | Zaurus Sl-5500 | - |
Related Weaknesses (CWE)
References
- http://online.securityfocus.com/archive/1/281437Broken LinkThird Party AdvisoryVDB Entry
- http://www.iss.net/security_center/static/9535.phpBroken Link
- http://www.securityfocus.com/bid/5201Broken LinkThird Party AdvisoryVDB Entry
- http://online.securityfocus.com/archive/1/281437Broken LinkThird Party AdvisoryVDB Entry
- http://www.iss.net/security_center/static/9535.phpBroken Link
- http://www.securityfocus.com/bid/5201Broken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2002-1975?
CVE-2002-1975 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via br...
How severe is CVE-2002-1975?
CVE-2002-1975 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1975?
Check the references section above for vendor advisories and patch information. Affected products include: Sharp Zaurus Sl-5000D Firmware, Sharp Zaurus Sl-5000D, Sharp Zaurus Sl-5500 Firmware, Sharp Zaurus Sl-5500.