{"api_version":"1","generated_at":"2026-07-23T07:31:16+00:00","cve":"CVE-2004-2079","urls":{"html":"https://cve.report/CVE-2004-2079","api":"https://cve.report/api/cve/CVE-2004-2079.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2079","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2079"},"summary":{"title":"CVE-2004-2079","description":"Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-02-09 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securiteam.com/securitynews/5SP0C0KC0A.html","name":"http://www.securiteam.com/securitynews/5SP0C0KC0A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"'Red-M Red-Alert Multiple Vulnerabilities' - SecuriTeam","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/3952","name":"http://www.osvdb.org/3952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://genhex.org/releases/031003.txt","name":"http://genhex.org/releases/031003.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1009001","name":"http://securitytracker.com/id?1009001","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - Red-M Red-Alert Can Be Rebooted By Remote Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9618","name":"http://www.securityfocus.com/bid/9618","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Multiple Red-M Red-Alert Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=full-disclosure&m=107635119005407&w=2","name":"http://marc.info/?l=full-disclosure&m=107635119005407&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[Full-Disclosure] Red-M Red-Alert Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/353211","name":"http://www.securityfocus.com/archive/1/353211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15088","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15088","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2079","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2079","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2079","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"red-m","cpe5":"red-alert","cpe6":"2.7.5_v3.1_build_24","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:15:01.217Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040209 Red-M Red-Alert Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/353211"},{"name":"20040209 Red-M Red-Alert Multiple Vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://marc.info/?l=full-disclosure&m=107635119005407&w=2"},{"name":"3952","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/3952"},{"name":"1009001","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1009001"},{"name":"9618","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9618"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securiteam.com/securitynews/5SP0C0KC0A.html"},{"name":"redalert-gain-access(15088)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15088"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://genhex.org/releases/031003.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-02-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040209 Red-M Red-Alert Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/353211"},{"name":"20040209 Red-M Red-Alert Multiple Vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://marc.info/?l=full-disclosure&m=107635119005407&w=2"},{"name":"3952","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/3952"},{"name":"1009001","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1009001"},{"name":"9618","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9618"},{"tags":["x_refsource_MISC"],"url":"http://www.securiteam.com/securitynews/5SP0C0KC0A.html"},{"name":"redalert-gain-access(15088)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15088"},{"tags":["x_refsource_MISC"],"url":"http://genhex.org/releases/031003.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2079","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040209 Red-M Red-Alert Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/353211"},{"name":"20040209 Red-M Red-Alert Multiple Vulnerabilities","refsource":"FULLDISC","url":"http://marc.info/?l=full-disclosure&m=107635119005407&w=2"},{"name":"3952","refsource":"OSVDB","url":"http://www.osvdb.org/3952"},{"name":"1009001","refsource":"SECTRACK","url":"http://securitytracker.com/id?1009001"},{"name":"9618","refsource":"BID","url":"http://www.securityfocus.com/bid/9618"},{"name":"http://www.securiteam.com/securitynews/5SP0C0KC0A.html","refsource":"MISC","url":"http://www.securiteam.com/securitynews/5SP0C0KC0A.html"},{"name":"redalert-gain-access(15088)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15088"},{"name":"http://genhex.org/releases/031003.txt","refsource":"MISC","url":"http://genhex.org/releases/031003.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2079","datePublished":"2005-05-19T04:00:00.000Z","dateReserved":"2005-05-19T00:00:00.000Z","dateUpdated":"2024-08-08T01:15:01.217Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-02-09 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:red-m:red-alert:2.7.5_v3.1_build_24:*:*:*:*:*:*:*","matchCriteriaId":"F44FF4B3-EB52-4315-8BFA-5ABA5668477F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2079","Ordinal":"1","Title":"CVE-2004-2079","CVE":"CVE-2004-2079","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2079","Ordinal":"1","NoteData":"Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.","Type":"Description","Title":"CVE-2004-2079"},{"CveYear":"2004","CveId":"2079","Ordinal":"2","NoteData":"2005-05-19","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2079","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}