{"api_version":"1","generated_at":"2026-07-23T03:59:59+00:00","cve":"CVE-2002-1797","urls":{"html":"https://cve.report/CVE-2002-1797","api":"https://cve.report/api/cve/CVE-2002-1797.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1797","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1797"},"summary":{"title":"CVE-2002-1797","description":"ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://online.securityfocus.com/archive/1/284648","name":"http://online.securityfocus.com/archive/1/284648","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.phenoelit.de/stuff/HP_Chai.txt","name":"http://www.phenoelit.de/stuff/HP_Chai.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PHENOELIT","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/5332","name":"http://www.securityfocus.com/bid/5332","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP ChaiVM ChaiServer Arbitrary Service Modification Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.iss.net/security_center/static/9694.php","name":"http://www.iss.net/security_center/static/9694.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: hp-chaivm-unauth-access (9694): HP ChaiVM could allow unauthorized access to services","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1797","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1797","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1797","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"chaivm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:34:56.255Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"hp-chaivm-unauth-access(9694)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9694.php"},{"name":"5332","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/5332"},{"name":"20020727 Phenoelit Advisory #0815 +--","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/284648"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.phenoelit.de/stuff/HP_Chai.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-07-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-06-15T16:39:11.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"hp-chaivm-unauth-access(9694)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9694.php"},{"name":"5332","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/5332"},{"name":"20020727 Phenoelit Advisory #0815 +--","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/284648"},{"tags":["x_refsource_MISC"],"url":"http://www.phenoelit.de/stuff/HP_Chai.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1797","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"hp-chaivm-unauth-access(9694)","refsource":"XF","url":"http://www.iss.net/security_center/static/9694.php"},{"name":"5332","refsource":"BID","url":"http://www.securityfocus.com/bid/5332"},{"name":"20020727 Phenoelit Advisory #0815 +--","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/284648"},{"name":"http://www.phenoelit.de/stuff/HP_Chai.txt","refsource":"MISC","url":"http://www.phenoelit.de/stuff/HP_Chai.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1797","datePublished":"2005-06-28T04:00:00.000Z","dateReserved":"2005-06-29T00:00:00.000Z","dateUpdated":"2024-08-08T03:34:56.255Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:chaivm:*:*:*:*:*:*:*:*","matchCriteriaId":"AFA8AD68-F38D-4049-8124-5EFAFC5A8C4C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1797","Ordinal":"1","Title":"CVE-2002-1797","CVE":"CVE-2002-1797","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1797","Ordinal":"1","NoteData":"ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer.","Type":"Description","Title":"CVE-2002-1797"},{"CveYear":"2002","CveId":"1797","Ordinal":"2","NoteData":"2005-06-28","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1797","Ordinal":"3","NoteData":"2021-06-15","Type":"Other","Title":"Modified"}]}}}