CVE-2004-1685
Summary
| CVE | CVE-2004-1685 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-09-15 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Smc Networks | Smc7004vwbr | 1.21a | All | All | All |
| Hardware | Smc Networks | Smc7004vwbr | 1.22 | All | All | All |
| Hardware | Smc Networks | Smc7004vwbr | 1.23 | All | All | All |
| Hardware | Smc Networks | Smc7008abr | 1.32 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/10088 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Secunia - Advisories - SMC Broadband Routers Session Handling Security Bypass | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Patch, Vendor Advisory |
| 'SMC7004VWBR / SMC7008ABR "spoofing" vulnerability.' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.