{"api_version":"1","generated_at":"2026-07-23T09:58:54+00:00","cve":"CVE-2005-2424","urls":{"html":"https://cve.report/CVE-2005-2424","api":"https://cve.report/api/cve/CVE-2005-2424.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2424","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2424"},"summary":{"title":"CVE-2005-2424","description":"The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/14372","name":"http://www.securityfocus.com/bid/14372","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/18294","name":"http://www.osvdb.org/18294","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securenetwork.it/advisories/","name":"http://www.securenetwork.it/advisories/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":":: Secure Network :: Security Research Advisories.","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21552","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21552","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112230914431638&w=2","name":"http://marc.info/?l=bugtraq&m=112230914431638&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16215","name":"http://secunia.com/advisories/16215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Siemens Santis 50 Authentication Bypass Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2424","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2424","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2424","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"siemens","cpe5":"santis_50","cpe6":"4.2.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:22:49.210Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"santis50-packet-gain-access(21552)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21552"},{"name":"16215","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16215"},{"name":"18294","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18294"},{"name":"14372","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14372"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securenetwork.it/advisories/"},{"name":"20050725 Siemens SANTIS 50 Authentication Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112230914431638&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"santis50-packet-gain-access(21552)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21552"},{"name":"16215","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16215"},{"name":"18294","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18294"},{"name":"14372","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14372"},{"tags":["x_refsource_MISC"],"url":"http://www.securenetwork.it/advisories/"},{"name":"20050725 Siemens SANTIS 50 Authentication Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112230914431638&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2424","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"santis50-packet-gain-access(21552)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21552"},{"name":"16215","refsource":"SECUNIA","url":"http://secunia.com/advisories/16215"},{"name":"18294","refsource":"OSVDB","url":"http://www.osvdb.org/18294"},{"name":"14372","refsource":"BID","url":"http://www.securityfocus.com/bid/14372"},{"name":"http://www.securenetwork.it/advisories/","refsource":"MISC","url":"http://www.securenetwork.it/advisories/"},{"name":"20050725 Siemens SANTIS 50 Authentication Vulnerability","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112230914431638&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2424","datePublished":"2005-08-03T04:00:00.000Z","dateReserved":"2005-08-03T00:00:00.000Z","dateUpdated":"2024-08-07T22:22:49.210Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:siemens:santis_50:4.2.8.0:*:*:*:*:*:*:*","matchCriteriaId":"781F6738-836C-468C-97CF-DC3EFB9455B0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2424","Ordinal":"1","Title":"CVE-2005-2424","CVE":"CVE-2005-2424","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2424","Ordinal":"1","NoteData":"The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.","Type":"Description","Title":"CVE-2005-2424"},{"CveYear":"2005","CveId":"2424","Ordinal":"2","NoteData":"2005-08-03","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2424","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}