Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/353211 | Vendor Advisory |
http://genhex.org/releases/031003.txt | Vendor Advisory |
http://www.securiteam.com/securitynews/5SP0C0KC0A.html | Vendor Advisory |
http://www.securityfocus.com/bid/9618 | Vendor Advisory |
http://securitytracker.com/id?1009001 | Exploit Patch Vendor Advisory |
http://www.osvdb.org/3952 | |
http://marc.info/?l=full-disclosure&m=107635119005407&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15088 |
Configurations
Information
Published : 2004-02-08 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-2079
Mitre link : CVE-2004-2079
JSON object : View
CWE
Products Affected
red-m
- red-alert