Vulnerabilities > CVE-2004-0939 - Denial-Of-Service vulnerability in Instant Virtual Extranet
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via a brute force attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |