CVE-2004-0939
changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords…
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via a brute force attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- neoteris/instant virtual extranet
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109709990708794&w=2
- http://secunia.com/advisories/12752
- http://securitytracker.com/id?1011552
- http://www.gosecure.ca/SecInfo/gosecure-2004-10.txt
- http://www.osvdb.org/8365
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17629
- http://marc.info/?l=bugtraq&m=109709990708794&w=2
- http://secunia.com/advisories/12752
- http://securitytracker.com/id?1011552
- http://www.gosecure.ca/SecInfo/gosecure-2004-10.txt
- http://www.osvdb.org/8365
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17629
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.