CVE-2004-0944
Last modified
CVE-2004-0944 is a vulnerability of currently unknown severity. The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
- http://www.corsaire.com/advisories/c040817-002.txtVendor Advisory
- http://www.mitel.com/DocController?documentId=14223Patch, Vendor Advisory
- http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=enPatch, Vendor Advisory
- http://www.corsaire.com/advisories/c040817-002.txtVendor Advisory
- http://www.mitel.com/DocController?documentId=14223Patch, Vendor Advisory
- http://www.niscc.gov.uk/niscc/docs/re-20050228-00178.pdf?lang=enPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0944?
How severe is CVE-2004-0944?
How do I fix CVE-2004-0944?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0938FreeRADIUS before 1.0.1 allows remote attackers to cause a d…
- CVE-2004-0939changepassword.cgi in Neoteris Instant Virtual Extranet (IVE…
- CVE-2004-0940Buffer overflow in the get_tag function in mod_include for A…7.8
- CVE-2004-0941Multiple buffer overflows in the gd graphics library (libgd)…
- CVE-2004-0942Apache webserver 2.0.52 and earlier allows remote attackers …
- CVE-2004-0943Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2004-0945The web management interface for Mitel 3300 Integrated Commu…
- CVE-2004-0946rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64…
- CVE-2004-0947Buffer overflow in unarj before 2.63a-r2 allows remote attac…
- CVE-2004-0948Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2004-0949The smb_recv_trans2 function call in the samba filesystem (s…
- CVE-2004-0950NetOp Host before 7.65 build 2004278 allows remote attackers…
Are you affected by CVE-2004-0944?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
