{"api_version":"1","generated_at":"2026-07-23T05:57:55+00:00","cve":"CVE-2003-0174","urls":{"html":"https://cve.report/CVE-2003-0174","api":"https://cve.report/api/cve/CVE-2003-0174.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0174","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0174"},"summary":{"title":"CVE-2003-0174","description":"The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-05-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-346","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.ciac.org/ciac/bulletins/n-084.shtml","name":"http://www.ciac.org/ciac/bulletins/n-084.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"N-084: SGI nsd LDAP Implementation Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P","name":"ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11860","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11860","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7442","name":"http://www.securityfocus.com/bid/7442","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"SGI IRIX Name Service Daemon LDAP UserPassword Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0174","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0174","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"174","vulnerable":"1","versionEndIncluding":"6.5.19","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sgi","cpe5":"irix","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:43:36.087Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"7442","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7442"},{"name":"irix-ldap-authentication-bypass(11860)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11860"},{"name":"20030407-01-P","tags":["vendor-advisory","x_refsource_SGI","x_transferred"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P"},{"name":"N-084","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/n-084.shtml"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-04-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"7442","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7442"},{"name":"irix-ldap-authentication-bypass(11860)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11860"},{"name":"20030407-01-P","tags":["vendor-advisory","x_refsource_SGI"],"url":"ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P"},{"name":"N-084","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/n-084.shtml"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0174","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"7442","refsource":"BID","url":"http://www.securityfocus.com/bid/7442"},{"name":"irix-ldap-authentication-bypass(11860)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11860"},{"name":"20030407-01-P","refsource":"SGI","url":"ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P"},{"name":"N-084","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/n-084.shtml"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0174","datePublished":"2003-04-29T04:00:00.000Z","dateReserved":"2003-03-28T00:00:00.000Z","dateUpdated":"2024-08-08T01:43:36.087Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-05-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-346","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sgi:irix:*:*:*:*:*:*:*:*","versionEndIncluding":"6.5.19","matchCriteriaId":"1B5551AA-3C06-4500-B4A1-BA69CFB296A5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"174","Ordinal":"1","Title":"CVE-2003-0174","CVE":"CVE-2003-0174","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"174","Ordinal":"1","NoteData":"The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.","Type":"Description","Title":"CVE-2003-0174"},{"CveYear":"2003","CveId":"174","Ordinal":"2","NoteData":"2003-04-29","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"174","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}