7.5

CVE-2004-1811

The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hp ≫ Ssl Http Server Version 5.0
Hp ≫ Ssl Http Server Version 5.92
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.35% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0057.html
http://marc.info/?l=bugtraq&m=107936784030214&w=2
http://secunia.com/advisories/11126
http://www.ciac.org/ciac/bulletins/o-100.shtml
Patch
http://www.immunitysec.com/downloads/hp_http.sxw.pdf
Vendor Advisory
http://www.securityfocus.com/advisories/6448
http://www.securityfocus.com/bid/9859
Patch
http://www.tru64.org/stories.php?story=04/03/12/0204078
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/15466