Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
References
Link | Resource |
---|---|
http://genhex.org/releases/031003.txt | Vendor Advisory |
http://marc.info/?l=full-disclosure&m=107635119005407&w=2 | |
http://securitytracker.com/id?1009001 | Exploit Patch Vendor Advisory |
http://www.osvdb.org/3952 | |
http://www.securiteam.com/securitynews/5SP0C0KC0A.html | Vendor Advisory |
http://www.securityfocus.com/archive/1/353211 | Vendor Advisory |
http://www.securityfocus.com/bid/9618 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15088 | |
http://genhex.org/releases/031003.txt | Vendor Advisory |
http://marc.info/?l=full-disclosure&m=107635119005407&w=2 | |
http://securitytracker.com/id?1009001 | Exploit Patch Vendor Advisory |
http://www.osvdb.org/3952 | |
http://www.securiteam.com/securitynews/5SP0C0KC0A.html | Vendor Advisory |
http://www.securityfocus.com/archive/1/353211 | Vendor Advisory |
http://www.securityfocus.com/bid/9618 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15088 |
Configurations
History
20 Nov 2024, 23:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://genhex.org/releases/031003.txt - Vendor Advisory | |
References | () http://marc.info/?l=full-disclosure&m=107635119005407&w=2 - | |
References | () http://securitytracker.com/id?1009001 - Exploit, Patch, Vendor Advisory | |
References | () http://www.osvdb.org/3952 - | |
References | () http://www.securiteam.com/securitynews/5SP0C0KC0A.html - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/353211 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/9618 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/15088 - |
Information
Published : 2004-02-09 05:00
Updated : 2024-11-20 23:52
NVD link : CVE-2004-2079
Mitre link : CVE-2004-2079
CVE.ORG link : CVE-2004-2079
JSON object : View
Products Affected
red-m
- red-alert
CWE