VULNERABILITY INTELLIGENCE

CVE-2002-0507

CVSS score2.1 LOW
EPSS probability2.22%
CISA KEVNot currently listed
Published2002-08-12
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:N/I:P/A:N

Description

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Weakness classification

  • CWE-287: Improper Authentication

Primary references