{"api_version":"1","generated_at":"2026-07-23T06:09:56+00:00","cve":"CVE-2001-0903","urls":{"html":"https://cve.report/CVE-2001-0903","api":"https://cve.report/api/cve/CVE-2001-0903.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0903","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0903"},"summary":{"title":"CVE-2001-0903","description":"Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-11-20 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=100626641009560&w=2","name":"http://marc.info/?l=bugtraq&m=100626641009560&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'A Cryptanalysis of the High-bandwidth Digital Content Protection System' - MARC","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3558","name":"http://www.securityfocus.com/bid/3558","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Intel HDCP Authentication Linear Relation Between Keys Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.iss.net/security_center/static/7612.php","name":"http://www.iss.net/security_center/static/7612.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://nunce.org/hdcp/hdcp111901.htm","name":"http://nunce.org/hdcp/hdcp111901.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"A Cryptanalysis of the High-bandwidth Digital Content Protection System\n  PRESENTED AT ACM-CCS8 DRM WORKSHOP 11/5/2001","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0903","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0903","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"903","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intel","cpe5":"high-bandwidth_digital_content_protection","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:37:06.996Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://nunce.org/hdcp/hdcp111901.htm"},{"name":"hdcp-authentication-keys(7612)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7612.php"},{"name":"3558","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3558"},{"name":"20011120 A Cryptanalysis of the High-bandwidth Digital Content Protection System","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=100626641009560&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-11-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://nunce.org/hdcp/hdcp111901.htm"},{"name":"hdcp-authentication-keys(7612)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7612.php"},{"name":"3558","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3558"},{"name":"20011120 A Cryptanalysis of the High-bandwidth Digital Content Protection System","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=100626641009560&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0903","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://nunce.org/hdcp/hdcp111901.htm","refsource":"MISC","url":"http://nunce.org/hdcp/hdcp111901.htm"},{"name":"hdcp-authentication-keys(7612)","refsource":"XF","url":"http://www.iss.net/security_center/static/7612.php"},{"name":"3558","refsource":"BID","url":"http://www.securityfocus.com/bid/3558"},{"name":"20011120 A Cryptanalysis of the High-bandwidth Digital Content Protection System","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=100626641009560&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0903","datePublished":"2002-02-02T05:00:00.000Z","dateReserved":"2002-01-31T00:00:00.000Z","dateUpdated":"2024-08-08T04:37:06.996Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-11-20 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:intel:high-bandwidth_digital_content_protection:1.0:*:*:*:*:*:*:*","matchCriteriaId":"C16A19D4-3B00-4872-A3B2-915B44321137"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"903","Ordinal":"1","Title":"CVE-2001-0903","CVE":"CVE-2001-0903","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"903","Ordinal":"1","NoteData":"Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.","Type":"Description","Title":"CVE-2001-0903"},{"CveYear":"2001","CveId":"903","Ordinal":"2","NoteData":"2002-02-02","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"903","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}