CVE-2002-1975
5.5 · MEDIUMOverview
CVE-2002-1975 is a medium-severity vulnerability affecting sharp zaurus_sl-5000d_firmware. It was published on December 31, 2002 and has a CVSS 3.1 base score of 5.5 (MEDIUM).
This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.
Technical Description
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.
Remediation
Check the references section for vendor advisories and patches from sharp. Update zaurus_sl-5000d_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
Frequently Asked Questions
What is CVE-2002-1975?
CVE-2002-1975 is a medium-severity vulnerability affecting sharp zaurus_sl-5000d_firmware. It was published on December 31, 2002 and has a CVSS 3.1 base score of 5.5 (MEDIUM).
How severe is CVE-2002-1975?
This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.
How do I fix or remediate CVE-2002-1975?
Check the references section for vendor advisories and patches from sharp. Update zaurus_sl-5000d_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2002-1975?
CyberStrike's AI-powered security agents can automatically detect CVE-2002-1975 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related MEDIUM CVEs from 2002
View all →An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypte
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow loc
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage ac
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the password
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a mes
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home dir
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user password
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by u
tip on multiple BSD-based operating systems allows local users to cause a denial of service (executi
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" opt
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for