Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2004-2761

42
FAUCET Score

CVE-2004-2761 describes a critical weakness in the MD5 Message-Digest Algorithm, specifically its lack of collision resistance, which can be exploited in X.509 certificate signature algorithms. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with a low attack complexity and the potential for integrity compromise (spoofing attacks) without requiring authentication. While not listed in CISA's KEV catalog, public exploit code for MD5 hash collisions exists, though there is minimal community discussion or media coverage surrounding this specific CVE.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:ietf:md5:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
9.93%
Probability of exploitation in next 30 days
EPSS Percentile
95.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-24807 · Dec 7, 2004
This CVE's current EPSS score of 0.0993 is in the 91st percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-common-0:7.3.0-41.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-util-0:7.3.0-21.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-21.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 8Fixed in: pki-common-0:8.0.6-2.el5pki
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 8Fixed in: pki-util-0:8.0.5-1.el5pki
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 8Fixed in: pki-ca-0:8.0.7-1.el5pki
View patch

Vendor Advisories (1)

redhatCVE-2004-2761Moderate

MD5: MD5 Message-Digest Algorithm is not collision resistant

Dec 30, 2008

References

blog.mozilla.com / security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery
blogs.technet.com / swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx
blogs.verisign.com / ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
secunia.com / advisories/33826
secunia.com / advisories/34281
secunia.com / advisories/42181
securityreason.com / securityalert/4866
securitytracker.com / id
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
ics-cert.us-cert.gov / advisories/ICSMA-18-058-02
rhn.redhat.com / errata/RHSA-2010-0837.html
rhn.redhat.com / errata/RHSA-2010-0838.html
support.hpe.com / hpsc/doc/public/display
redhat.com / archives/fedora-package-announce/2009-February/msg00096.html
cisco.com / en/US/products/products_security_response09186a0080a5d24a.html
doxpara.com / research/md5/md5_someday.pdf
kb.cert.org / vuls/id/836068
Third Party AdvisoryUS Government Resource
microsoft.com / technet/security/advisory/961509.mspx
MitigationPatchVendor Advisory
phreedom.org / research/rogue-ca
securityfocus.com / archive/1/499685/100/0/threaded
securityfocus.com / bid/33065
ubuntu.com / usn/usn-740-1
win.tue.nl / hashclash/rogue-ca
win.tue.nl / hashclash/SoftIntCodeSign