7.5

CVE-2004-2079

Exploit
Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Red-mRed-alert Version2.7.5_v3.1_build_24
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.1% 0.793
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://genhex.org/releases/031003.txt
Vendor Advisory
http://marc.info/?l=full-disclosure&m=107635119005407&w=2
http://securitytracker.com/id?1009001
Patch
Vendor Advisory
Exploit
http://www.securiteam.com/securitynews/5SP0C0KC0A.html
Vendor Advisory
http://www.securityfocus.com/archive/1/353211
Vendor Advisory
http://www.securityfocus.com/bid/9618
Vendor Advisory
http://www.osvdb.org/3952
https://exchange.xforce.ibmcloud.com/vulnerabilities/15088