ID

VAR-200412-1172


CVE

CVE-2004-1814


TITLE

VocalTec VGW4/8 Telephony Gateway Remote Authentication Bypass Vulnerability

Trust: 0.9

sources: BID: 9876 // CNNVD: CNNVD-200412-520

DESCRIPTION

Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp. It has been reported that the VGW4/8 Telephony Gateway is prone to a remote authentication bypass vulnerability via its web configuration tool. The problem is due to a design error in the application that allows a user to access configuration pages without prior authentication. Successful exploitation of this issue may allow a remote attacker to gain control of the affected appliance via its web configuration tool

Trust: 1.26

sources: NVD: CVE-2004-1814 // BID: 9876 // VULHUB: VHN-10243

AFFECTED PRODUCTS

vendor:vocaltecmodel:vgw4 8 telephony gatewayscope:eqversion:8.0

Trust: 1.6

vendor:vocaltecmodel:vgw4/8 telephony gatewayscope: - version: -

Trust: 0.3

sources: BID: 9876 // CNNVD: CNNVD-200412-520 // NVD: CVE-2004-1814

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2004-1814
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200412-520
value: MEDIUM

Trust: 0.6

VULHUB: VHN-10243
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2004-1814
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-10243
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-10243 // CNNVD: CNNVD-200412-520 // NVD: CVE-2004-1814

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2004-1814

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200412-520

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-200412-520

EXTERNAL IDS

db:BIDid:9876

Trust: 2.0

db:NVDid:CVE-2004-1814

Trust: 1.7

db:CNNVDid:CNNVD-200412-520

Trust: 0.7

db:XFid:15476

Trust: 0.6

db:XFid:48

Trust: 0.6

db:BUGTRAQid:20040315 VOCALTEC GATEWAY 8 REVERSE DIRECTORY TRANSVERSAL + AUTHORIZATION BYPASS

Trust: 0.6

db:VULHUBid:VHN-10243

Trust: 0.1

sources: VULHUB: VHN-10243 // BID: 9876 // CNNVD: CNNVD-200412-520 // NVD: CVE-2004-1814

REFERENCES

url:http://www.securityfocus.com/bid/9876

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/15476

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=107936739131657&w=2

Trust: 1.0

url:http://xforce.iss.net/xforce/xfdb/15476

Trust: 0.6

url:http://marc.theaimsgroup.com/?l=bugtraq&m=107936739131657&w=2

Trust: 0.6

url:http://www.vocaltec.com/html/telephony/gateway_4_8.shtml

Trust: 0.3

url:/archive/1/357437

Trust: 0.3

url:http://marc.info/?l=bugtraq&m=107936739131657&w=2

Trust: 0.1

sources: VULHUB: VHN-10243 // BID: 9876 // CNNVD: CNNVD-200412-520 // NVD: CVE-2004-1814

CREDITS

This issue has been reported by "Rafel Ivgi, The-Insider" <theinsider@012.net.il>.

Trust: 0.9

sources: BID: 9876 // CNNVD: CNNVD-200412-520

SOURCES

db:VULHUBid:VHN-10243
db:BIDid:9876
db:CNNVDid:CNNVD-200412-520
db:NVDid:CVE-2004-1814

LAST UPDATE DATE

2024-08-14T14:53:47.335000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-10243date:2017-07-11T00:00:00
db:BIDid:9876date:2004-03-15T00:00:00
db:CNNVDid:CNNVD-200412-520date:2005-10-20T00:00:00
db:NVDid:CVE-2004-1814date:2017-07-11T01:31:22.233

SOURCES RELEASE DATE

db:VULHUBid:VHN-10243date:2004-12-31T00:00:00
db:BIDid:9876date:2004-03-15T00:00:00
db:CNNVDid:CNNVD-200412-520date:2004-12-31T00:00:00
db:NVDid:CVE-2004-1814date:2004-12-31T05:00:00