« Volver al listado

CVE-2004-0679

Estado: ModificadaMedia (5)—

The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2004-0679",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-08-06T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=108904813003166&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/560",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.bandecon.com/advisory/unreal.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/10663",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.unrealircd.com/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16610",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=108904813003166&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/560",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.bandecon.com/advisory/unreal.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/10663",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.unrealircd.com/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16610",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user's IP addresses."
    },
    {
      "lang": "es",
      "value": "La funcionalidad de encubrimiento de IP (cloak.c) en UnrealIRCd 3.2, y posiblemente otras versiones, utiliza una función hash débil para ocultar las direcciones IP, lo que podría permitir a atacantes remotos utilizar métodos de fuerza bruta para obtener las direcciones IP de otros usuarios."
    }
  ],
  "lastModified": "2026-06-16T22:06:08.863",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:unreal:unrealircd:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF8B42EE-E34A-4EAE-9C17-48329AD21AAC"
            },
            {
              "criteria": "cpe:2.3:a:unreal:unrealircd:3.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7963064-253D-423C-810E-5737530D458D"
            },
            {
              "criteria": "cpe:2.3:a:unreal:unrealircd:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBCDD11F-6B5E-4B9D-919B-86AA8ADB8B7B"
            },
            {
              "criteria": "cpe:2.3:a:unreal:unrealircd:3.2_.0_beta_10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6479BA75-BABF-44DF-82F8-0078BD93C291"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}