CVE-2004-0477
Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password. NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447. This candidate is ONLY for the ADSL router bypass.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.08% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- 3com/3cp4144
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/11716
- http://www.idefense.com/application/poi/display?id=106&type=vulnerabilities&flashstatus=falsePatch, Vendor Advisory
- http://www.securityfocus.com/bid/10426Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16267
- http://secunia.com/advisories/11716
- http://www.idefense.com/application/poi/display?id=106&type=vulnerabilities&flashstatus=falsePatch, Vendor Advisory
- http://www.securityfocus.com/bid/10426Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16267
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.