{ "id": "CVE-2004-0680", "sourceIdentifier": "cve@mitre.org", "published": "2004-08-06T04:00:00.000", "lastModified": "2017-07-11T01:30:22.417", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access." }, { "lang": "es", "value": "El m\u00f3dem ADSL Zoom X3 tiene un terminal en ejecuci\u00f3n por el puerto 254 que puede ser accedido utilizando la contrase\u00f1a de gesti\u00f3n HTML por defecto, incluso aunque haya sido cambiada a trav\u00e9s del interfaz HTML, lo que podr\u00eda obtener acceso no autorizado a atacantes remotos." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "availabilityImpact": "COMPLETE", "baseScore": 10.0 }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 10.0, "acInsufInfo": false, "obtainAllPrivilege": true, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:h:zoom:model_5560_x3_ethernet_adsl_modem:*:*:*:*:*:*:*:*", "matchCriteriaId": "2ACFA54E-21A0-42EE-8000-4DEA6D545C31" } ] } ] } ], "references": [ { "url": "http://marc.info/?l=bugtraq&m=108915255520924&w=2", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/10669", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16639", "source": "cve@mitre.org" } ] }