CVE-2004-0243 describes an information leakage vulnerability in IBM AIX versions 4.3.3 through 5.1. When direct remote login is disabled, the system provides a distinct error message if a correct password is entered, enabling remote attackers to conduct brute-force password guessing attacks. This vulnerability has a CVSS score of 5.0, indicating a medium severity, as it allows for partial confidentiality impact without requiring authentication or complex attack conditions. While no public exploit intelligence like Metasploit modules or ExploitDB entries exist, the CVE has garnered significant community discussion with 10 mentions, suggesting ongoing interest despite its age and inactive status on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* | ||
>= 4.3.3, <= 5.1CPE matchmatch criteria | cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.