CVE-2001-0903
Summary
| CVE | CVE-2001-0903 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-11-20 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Intel | High-bandwidth Digital Content Protection | 1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'A Cryptanalysis of the High-bandwidth Digital Content Protection System' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Intel HDCP Authentication Linear Relation Between Keys Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ISS X-Force Database: | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| A Cryptanalysis of the High-bandwidth Digital Content Protection System PRESENTED AT ACM-CCS8 DRM WORKSHOP 11/5/2001 | af854a3a-2127-422b-91ae-364da2661108 | nunce.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.