MEDIUM · 5.0

CVE-2004-0939

changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entere...

Vulnerability Description

changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via a brute force attack.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NeoterisInstant Virtual ExtranetAll versions

References

FAQ

What is CVE-2004-0939?

CVE-2004-0939 is a vulnerability with a CVSS score of 5.0 (MEDIUM). changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entere...

How severe is CVE-2004-0939?

CVE-2004-0939 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0939?

Check the references section above for vendor advisories and patch information. Affected products include: Neoteris Instant Virtual Extranet.