HIGH · 7.5

CVE-2004-2326

SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was late...

Vulnerability Description

SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Ip3 NetworksIp3 NetaccessAll versions
Ip3 NetworksIp3 Netaccess - HospitalityAll versions
Ip3 NetworksIp3 Netaccess - Wireless HotspotsAll versions

References

FAQ

What is CVE-2004-2326?

CVE-2004-2326 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was late...

How severe is CVE-2004-2326?

CVE-2004-2326 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2326?

Check the references section above for vendor advisories and patch information. Affected products include: Ip3 Networks Ip3 Netaccess, Ip3 Networks Ip3 Netaccess - Hospitality, Ip3 Networks Ip3 Netaccess - Wireless Hotspots.