{"api_version":"1","generated_at":"2026-07-24T20:33:47+00:00","cve":"CVE-2002-0134","urls":{"html":"https://cve.report/CVE-2002-0134","api":"https://cve.report/api/cve/CVE-2002-0134.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0134","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0134"},"summary":{"title":"CVE-2002-0134","description":"Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a \"dos\" command.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-03-25 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=101131669102843&w=2","name":"http://marc.info/?l=bugtraq&m=101131669102843&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Avirt Gateway Suite Remote SYSTEM Level Compromise' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=101424723728817&w=2","name":"http://marc.info/?l=bugtraq&m=101424723728817&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Avirt 4.2 question' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/7915.php","name":"http://www.iss.net/security_center/static/7915.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: avirt-gateway-telnet-access (7915): Avirt Gateway Suite telnet proxy could allow unauthorized access","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3901","name":"http://www.securityfocus.com/bid/3901","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Avirt Gateway Suite Telnet Proxy Remote SYSTEM Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0134","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0134","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"134","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"avirt","cpe5":"avirt_gateway_suite","cpe6":"4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:42:27.691Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3901","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3901"},{"name":"20020117 Avirt Gateway Suite Remote SYSTEM Level Compromise","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=101131669102843&w=2"},{"name":"avirt-gateway-telnet-access(7915)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7915.php"},{"name":"20020220 Avirt 4.2 question","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=101424723728817&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-01-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a \"dos\" command."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3901","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3901"},{"name":"20020117 Avirt Gateway Suite Remote SYSTEM Level Compromise","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=101131669102843&w=2"},{"name":"avirt-gateway-telnet-access(7915)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7915.php"},{"name":"20020220 Avirt 4.2 question","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=101424723728817&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0134","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a \"dos\" command."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3901","refsource":"BID","url":"http://www.securityfocus.com/bid/3901"},{"name":"20020117 Avirt Gateway Suite Remote SYSTEM Level Compromise","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=101131669102843&w=2"},{"name":"avirt-gateway-telnet-access(7915)","refsource":"XF","url":"http://www.iss.net/security_center/static/7915.php"},{"name":"20020220 Avirt 4.2 question","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=101424723728817&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0134","datePublished":"2002-03-15T05:00:00.000Z","dateReserved":"2002-03-15T00:00:00.000Z","dateUpdated":"2024-08-08T02:42:27.691Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-03-25 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:avirt:avirt_gateway_suite:4.2:*:*:*:*:*:*:*","matchCriteriaId":"E44ECB72-BA5B-4BB4-86C7-2FF9F285229B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"134","Ordinal":"1","Title":"CVE-2002-0134","CVE":"CVE-2002-0134","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"134","Ordinal":"1","NoteData":"Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a \"dos\" command.","Type":"Description","Title":"CVE-2002-0134"},{"CveYear":"2002","CveId":"134","Ordinal":"2","NoteData":"2002-03-15","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"134","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}