Vulnerability Details CVE-2004-1182
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.0%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-1182
-
cpe:2.3:a:hylafax:hylafax:4.1.1
-
cpe:2.3:a:hylafax:hylafax:4.1.2
-
cpe:2.3:a:hylafax:hylafax:4.1.3
-
cpe:2.3:a:hylafax:hylafax:4.1.5
-
cpe:2.3:a:hylafax:hylafax:4.1.6
-
cpe:2.3:a:hylafax:hylafax:4.1.7
-
cpe:2.3:a:hylafax:hylafax:4.1.8
-
cpe:2.3:a:hylafax:hylafax:4.1_beta1
-
cpe:2.3:a:hylafax:hylafax:4.1_beta2
-
cpe:2.3:a:hylafax:hylafax:4.1_beta3
-
cpe:2.3:a:hylafax:hylafax:4.2.0