CVE-2004-1022
Estado: ModificadaBaja (2.1)—
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2004-1022",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-01-10T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=110304957607578&w=2",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18470",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=110304957607578&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18470",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software."
},
{
"lang": "es",
"value": "Kerio Winroute Firewall anteriores a 6.0.7, ServerFirewall anteriores a 1.0.1, y MailServer anteriores a 6.0.5 usan cifrado simétrico para contraseñas de usuario, lo que permite a atacantes descifrar la base de datos de usuarios y obtener las contraseñas extrayendo la clave secreta del software."
}
],
"lastModified": "2026-06-16T22:06:52.383",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7D26DCD-85B0-4908-A414-119862437C28"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B58BAF1-CF68-4F8C-8BCD-FF3C015FE72A"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B9C9084-B518-44F2-9F65-032A644FEC61"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F55CFA68-E07E-46CE-87F6-00AE9A268CE2"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58ECCE69-EAB9-427E-8922-F463E184C9F7"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20E50A0F-7AFF-4F17-8833-839DDBD538C7"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9063B23B-E585-41E4-98FF-DF18602C6E6E"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CB993B9-0CF5-4E71-A612-F3033F4F202B"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B079207-FAF3-4FE2-B420-342440958C48"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8A82C0BC-50D5-4FAC-A654-387B49CB7047"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BC1748E-32F0-4144-A597-89E8B8705FFA"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39C92F3B-23E3-4978-89AA-FC17B8EDF580"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B1FA201-CBCF-4D61-9848-F661A16EBEF7"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A2154DF-2306-4E8B-B78A-1BF20E697157"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79C4389A-4BF4-4C38-8FF5-72B92548EFB4"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67230E76-2C30-4038-BC5B-BAC02EDDFAC3"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:5.7.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FAEA1EB3-5F4F-40D6-833C-225AC348760D"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC515E75-119E-4CB9-985E-00E6A9349178"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "937A6092-48C9-4721-B069-0B46D3520E36"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F38A0AAC-ACA8-44D3-B36A-741D01BE166F"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:6.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08AE0CAA-B5A4-4E3A-B997-A2858E88CCC8"
},
{
"criteria": "cpe:2.3:a:kerio:kerio_mailserver:6.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9AC0D46-2096-4006-8FED-A67AFCE2ED98"
},
{
"criteria": "cpe:2.3:a:kerio:serverfirewall:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB482850-6F0E-484A-B7CA-B8CBCBDBBC8B"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6E5A18A-572A-4914-8AC7-AEF02C760574"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B5158D0-ED2B-4716-8A81-385562566A7B"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F53C7737-404A-4EB3-9A1B-0091116D8CCE"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4A47DCB-50D3-4CC0-874C-39FF8D09B2EC"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE437407-E9D3-41A7-B5BF-62CD861B3830"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "810364F5-B6FA-47A2-A5DE-F886CEF1ED70"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FEE280A4-C218-4D2F-88E3-718F19F0E4B5"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A591237E-DBA8-42F3-B4A2-BFD537AE0A20"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEC5DAFA-24B9-4C5D-8F7B-9DDDDFAA2342"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E56C041A-5D92-4B7F-9962-A083E883EA8E"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7223D79B-F096-4265-8D80-F5A41E5A1B1E"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC9F17CE-B48E-45A2-BFC9-0D27AF032F36"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D33CD1F-105E-43CC-B135-76E0AC8CACD1"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95F501CC-BD8E-460F-9251-B492C979676E"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B84BE69E-9760-4ABE-A8C6-C96AD4ACB56A"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD36E240-FDBB-4EB8-B2C2-7B59715EEDF1"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9DD7AF9A-54CD-4D15-9D41-D740CC48FF1B"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6D7D55B-887B-479D-9067-0CE457C25561"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "705BC91B-4583-418D-BF68-B219BC04EB42"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.1.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9E1D191B-ACAF-4871-B553-A55F99827EF2"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:5.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C7727351-0ED7-45DD-82DE-0FEE92699927"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "563E83E1-74C0-4312-A5C5-0223ADE55F65"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE079B94-A8C6-41E7-98B1-29A4DE4F66EC"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94AC89E5-8B9C-4C6B-8976-6A4A6F922858"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B99A154-D3C6-4B1C-BEC9-7D1AEAFCAC41"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0ADAAD5F-3286-464E-A309-9454EE9A663F"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE1437DE-E19A-4C2C-9077-DB1FF48772C0"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D0089BE-856D-4998-BBFE-1F626A43377E"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CE81F49-05CE-4987-90C0-B6D077B65DD9"
},
{
"criteria": "cpe:2.3:a:kerio:winroute_firewall:6.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "650E19BC-6545-45E9-BE2B-0900323C80C1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}