HIGH · 9.3

CVE-2010-0833

The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPas...

Vulnerability Description

The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
LikewiseLikewise Open5.4
LikewiseLikewise Cifs5.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0833?

CVE-2010-0833 is a vulnerability with a CVSS score of 9.3 (HIGH). The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPas...

How severe is CVE-2010-0833?

CVE-2010-0833 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0833?

Check the references section above for vendor advisories and patch information. Affected products include: Likewise Likewise Open, Likewise Likewise Cifs.