CVE-2004-0952 describes a vulnerability in HP-UX B.11.00 through B.11.23 when using Ignite-UX's add_new_client command, which incorrectly sets world-writable permissions on parts of the TFTP server's directory tree. This allows unauthenticated remote attackers to modify data or exhaust disk space, posing a partial impact to integrity and availability. While the CVSS score is 6.4 (medium), its FAUCET Risk Score is high at 80/100, indicating significant concern. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit or ExploitDB, though it has garnered notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.00CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* | ||
11.11CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:* | ||
11.22CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.22:*:*:*:*:*:*:* | ||
11.23CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.23:*:ia64_64-bit:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.