SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-1511

Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

MEDIUM 5.0EPSS 2.32%

Does this matter?

Lower severity and a low EPSS score (2.32%). Track it; it rarely justifies an emergency change on its own.

Description

Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.32% probability · 82th percentile
CISA KEV
Not listed
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.