CVE-2004-1685
SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- smc networks/smc7004vwbr · smc networks/smc7008abr
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109526094614160&w=2
- http://secunia.com/advisories/12601Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/10088
- http://www.securityfocus.com/bid/11197Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17443
- http://marc.info/?l=bugtraq&m=109526094614160&w=2
- http://secunia.com/advisories/12601Exploit, Patch, Vendor Advisory
- http://www.osvdb.org/10088
- http://www.securityfocus.com/bid/11197Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17443
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.