CVE-2004-2079
Summary
| CVE | CVE-2004-2079 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-02-09 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'Red-M Red-Alert Multiple Vulnerabilities' - SecuriTeam | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | Vendor Advisory |
| www.osvdb.org/3952 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| genhex.org/releases/031003.txt | af854a3a-2127-422b-91ae-364da2661108 | genhex.org | Vendor Advisory |
| SecurityTracker.com Archives - Red-M Red-Alert Can Be Rebooted By Remote Users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit, Patch, Vendor Advisory |
| Multiple Red-M Red-Alert Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| '[Full-Disclosure] Red-M Red-Alert Multiple Vulnerabilities' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.