{"api_version":"1","generated_at":"2026-07-23T05:39:52+00:00","cve":"CVE-2002-0054","urls":{"html":"https://cve.report/CVE-2002-0054","api":"https://cve.report/api/cve/CVE-2002-0054.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0054","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0054"},"summary":{"title":"CVE-2002-0054","description":"SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-03-08 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-294","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Microsoft Security Bulletin MS02-011 - Low | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4205","name":"http://www.securityfocus.com/bid/4205","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","VDB Entry"],"title":"Microsoft Windows SMTP Service Authorization Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=101501580409373&w=2","name":"http://marc.info/?l=bugtraq&m=101501580409373&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"'IIS SMTP component allows mail relaying via Null Session' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0054","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0054","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"-","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"exchange_server","cpe6":"5.5","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"-","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"54","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"-","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:35:17.425Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020301 IIS SMTP component allows mail relaying via Null Session","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=101501580409373&w=2"},{"name":"MS02-011","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011"},{"name":"4205","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4205"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-02-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2003-03-19T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020301 IIS SMTP component allows mail relaying via Null Session","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=101501580409373&w=2"},{"name":"MS02-011","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011"},{"name":"4205","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4205"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0054","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020301 IIS SMTP component allows mail relaying via Null Session","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=101501580409373&w=2"},{"name":"MS02-011","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-011"},{"name":"4205","refsource":"BID","url":"http://www.securityfocus.com/bid/4205"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0054","datePublished":"2003-04-02T05:00:00.000Z","dateReserved":"2002-02-02T00:00:00.000Z","dateUpdated":"2024-08-08T02:35:17.425Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-03-08 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-294","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:-:*:*:*:*:*:*","matchCriteriaId":"B4F9C143-4734-4E5D-9281-F51513C5CAAF"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp1:*:*:*:*:*:*","matchCriteriaId":"AD3E2F18-A369-4767-ACEF-38DB40EEC6D4"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp2:*:*:*:*:*:*","matchCriteriaId":"EC01670D-4550-4034-86A5-7879B6334241"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp3:*:*:*:*:*:*","matchCriteriaId":"B80A57A1-7B9F-4C07-ADAA-DBC4687F1EFC"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:exchange_server:5.5:sp4:*:*:*:*:*:*","matchCriteriaId":"E3983529-F4E3-4883-97AF-5BFC87AC3E86"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*","matchCriteriaId":"685F1981-EA61-4A00-89F8-A748A88962F8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:-:sp1:*:*:*:*:*:*","matchCriteriaId":"A23A90DA-6E38-4479-926A-BD29F438F602"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_2000:-:sp2:*:*:*:*:*:*","matchCriteriaId":"FF99A17F-9469-4937-A23B-FD5C8B37087B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"54","Ordinal":"1","Title":"CVE-2002-0054","CVE":"CVE-2002-0054","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"54","Ordinal":"1","NoteData":"SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.","Type":"Description","Title":"CVE-2002-0054"},{"CveYear":"2002","CveId":"54","Ordinal":"2","NoteData":"2003-04-02","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"54","Ordinal":"3","NoteData":"2003-03-18","Type":"Other","Title":"Modified"}]}}}