{"api_version":"1","generated_at":"2026-07-23T10:12:48+00:00","cve":"CVE-2002-2037","urls":{"html":"https://cve.report/CVE-2002-2037","api":"https://cve.report/api/cve/CVE-2002-2037.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-2037","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-2037"},"summary":{"title":"CVE-2002-2037","description":"The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.iss.net/security_center/static/7912.php","name":"http://www.iss.net/security_center/static/7912.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"ISS X-Force Database: cisco-mgc-exposure (7912): Cisco MGC (Media Gateway Controller) Solaris 2.6 exposure","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.cisco.com/warp/public/707/Solaris-for-MGC-pub.shtml","name":"http://www.cisco.com/warp/public/707/Solaris-for-MGC-pub.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Cisco - Hardening of Solaris OS for MGC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3897","name":"http://www.securityfocus.com/bid/3897","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Cisco Media Gateway Controller Solaris Vulnerability Exposure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-2037","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-2037","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"2037","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"bams","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2037","vulnerable":"1","versionEndIncluding":"9.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"pgw_2200","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2037","vulnerable":"1","versionEndIncluding":"7.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"sc2200","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2037","vulnerable":"1","versionEndIncluding":"9.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"vsc3000","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"2037","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"vspt","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:51:17.130Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"cisco-mgc-exposure(7912)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/7912.php"},{"name":"20020116 Hardening of Solaris OS for MGC","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/Solaris-for-MGC-pub.shtml"},{"name":"3897","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3897"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-07-14T04:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"cisco-mgc-exposure(7912)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/7912.php"},{"name":"20020116 Hardening of Solaris OS for MGC","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/Solaris-for-MGC-pub.shtml"},{"name":"3897","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3897"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-2037","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cisco-mgc-exposure(7912)","refsource":"XF","url":"http://www.iss.net/security_center/static/7912.php"},{"name":"20020116 Hardening of Solaris OS for MGC","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/Solaris-for-MGC-pub.shtml"},{"name":"3897","refsource":"BID","url":"http://www.securityfocus.com/bid/3897"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-2037","datePublished":"2005-07-14T04:00:00.000Z","dateReserved":"2005-07-14T00:00:00.000Z","dateUpdated":"2024-09-16T19:50:51.832Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:bams:*:*:*:*:*:*:*:*","matchCriteriaId":"65412341-C475-44AD-8CEA-DE5BB43E342D"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:pgw_2200:*:*:*:*:*:*:*:*","versionEndIncluding":"9.1","matchCriteriaId":"C412A9AD-5E06-4DC0-BD1D-005761137699"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:sc2200:*:*:*:*:*:*:*:*","versionEndIncluding":"7.4","matchCriteriaId":"B1B16DA7-CE36-436D-8D06-58EADD930587"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:vsc3000:*:*:*:*:*:*:*:*","versionEndIncluding":"9.1","matchCriteriaId":"B676067F-A013-4E06-86EE-4121BB54FA7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:vspt:*:*:*:*:*:*:*:*","matchCriteriaId":"752E6984-859E-4B9C-A839-BFB317F9B703"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"2037","Ordinal":"1","Title":"CVE-2002-2037","CVE":"CVE-2002-2037","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"2037","Ordinal":"1","NoteData":"The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities.","Type":"Description","Title":"CVE-2002-2037"},{"CveYear":"2002","CveId":"2037","Ordinal":"2","NoteData":"2005-07-14","Type":"Other","Title":"Published"}]}}}