{"api_version":"1","generated_at":"2026-07-23T12:22:40+00:00","cve":"CVE-2003-1363","urls":{"html":"https://cve.report/CVE-2003-1363","api":"https://cve.report/api/cve/CVE-2003-1363.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1363","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1363"},"summary":{"title":"CVE-2003-1363","description":"The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.iss.net/security_center/static/11310.php","name":"http://www.iss.net/security_center/static/11310.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database:abyss-web-admin-bruteforce(11310): Abyss Web Server Web management interface brute force attack","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6842","name":"http://www.securityfocus.com/bid/6842","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Abyss Web Server Administrative Interface Failed Login Recording Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html","name":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - Abyss WebServer Brute Force Vulnerability - From tgadams_at_bellsouth.net","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1363","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1363","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1363","vulnerable":"1","versionEndIncluding":"1.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aprelium_technologies","cpe5":"abyss_web_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:28:03.294Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"abyss-web-admin-bruteforce(11310)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/11310.php"},{"name":"20030212 Abyss WebServer Brute Force Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html"},{"name":"6842","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6842"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-10-17T01:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"abyss-web-admin-bruteforce(11310)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/11310.php"},{"name":"20030212 Abyss WebServer Brute Force Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html"},{"name":"6842","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6842"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1363","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"abyss-web-admin-bruteforce(11310)","refsource":"XF","url":"http://www.iss.net/security_center/static/11310.php"},{"name":"20030212 Abyss WebServer Brute Force Vulnerability","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2003-02/0149.html"},{"name":"6842","refsource":"BID","url":"http://www.securityfocus.com/bid/6842"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1363","datePublished":"2007-10-17T01:00:00.000Z","dateReserved":"2007-10-16T00:00:00.000Z","dateUpdated":"2024-09-17T03:18:25.925Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aprelium_technologies:abyss_web_server:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1.2","matchCriteriaId":"5D18F091-C79E-4493-8D7C-79938C3784D2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1363","Ordinal":"1","Title":"CVE-2003-1363","CVE":"CVE-2003-1363","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1363","Ordinal":"1","NoteData":"The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.","Type":"Description","Title":"CVE-2003-1363"},{"CveYear":"2003","CveId":"1363","Ordinal":"2","NoteData":"2007-10-16","Type":"Other","Title":"Published"}]}}}