VulnerabilityModified
CVE-2004-1855
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
MEDIUM 5.0EPSS 2.61%
Does this matter?
Lower severity and a low EPSS score (2.61%). Track it; it rarely justifies an emergency change on its own.
Description
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- mythic entertainment/dark age of camelot
- Source
- cve@mitre.org
References
- http://capnbry.net/daoc/advisory20040323/Exploit, Vendor Advisory
- http://lists.netsys.com/pipermail/full-disclosure/2004-March/019212.html
- http://marc.info/?l=bugtraq&m=108016932816707&w=2
- http://www.securityfocus.com/bid/9960Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15597
- http://capnbry.net/daoc/advisory20040323/Exploit, Vendor Advisory
- http://lists.netsys.com/pipermail/full-disclosure/2004-March/019212.html
- http://marc.info/?l=bugtraq&m=108016932816707&w=2
- http://www.securityfocus.com/bid/9960Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15597
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.