{"api_version":"1","generated_at":"2026-07-23T10:42:29+00:00","cve":"CVE-2003-1417","urls":{"html":"https://cve.report/CVE-2003-1417","api":"https://cve.report/api/cve/CVE-2003-1417.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1417","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1417"},"summary":{"title":"CVE-2003-1417","description":"nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.4","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.ncipher.com/support/advisories/advisory7_keyduplicates.html","name":"http://www.ncipher.com/support/advisories/advisory7_keyduplicates.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Unexpected duplicates of imported software based keys","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6927","name":"http://www.securityfocus.com/bid/6927","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"nCipher Support Software Key Import Temporary File Cleanup Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11422","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11422","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=104619088801750&w=2","name":"http://marc.info/?l=bugtraq&m=104619088801750&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'nCipher Advisory #7: Unexpected copies of imported software keys' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1417","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1417","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncipher","cpe5":"support_software","cpe6":"6.00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:28:03.471Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"6927","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6927"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ncipher.com/support/advisories/advisory7_keyduplicates.html"},{"name":"ncipher-duplicate-keys(11422)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11422"},{"name":"20030225 nCipher Advisory #7: Unexpected copies of imported software keys","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104619088801750&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-02-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"6927","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6927"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ncipher.com/support/advisories/advisory7_keyduplicates.html"},{"name":"ncipher-duplicate-keys(11422)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11422"},{"name":"20030225 nCipher Advisory #7: Unexpected copies of imported software keys","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=104619088801750&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1417","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"6927","refsource":"BID","url":"http://www.securityfocus.com/bid/6927"},{"name":"http://www.ncipher.com/support/advisories/advisory7_keyduplicates.html","refsource":"CONFIRM","url":"http://www.ncipher.com/support/advisories/advisory7_keyduplicates.html"},{"name":"ncipher-duplicate-keys(11422)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11422"},{"name":"20030225 nCipher Advisory #7: Unexpected copies of imported software keys","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=104619088801750&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1417","datePublished":"2007-10-20T10:00:00.000Z","dateReserved":"2007-10-19T00:00:00.000Z","dateUpdated":"2024-08-08T02:28:03.471Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","baseScore":4.4,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ncipher:support_software:6.00:*:*:*:*:*:*:*","matchCriteriaId":"67017884-F2CD-4795-B1DF-726260CB6D7F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1417","Ordinal":"1","Title":"CVE-2003-1417","CVE":"CVE-2003-1417","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1417","Ordinal":"1","NoteData":"nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.","Type":"Description","Title":"CVE-2003-1417"},{"CveYear":"2003","CveId":"1417","Ordinal":"2","NoteData":"2007-10-20","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1417","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}