CVE-2004-1328 describes an unspecified vulnerability within the newgrp utility in HP-UX versions B.11.00, B.11.04, and B.11.11, which allows local users to escalate privileges. With a CVSS score of 7.2, this vulnerability is considered high severity, indicating that an attacker with local access can achieve complete confidentiality, integrity, and availability compromise with low attack complexity. Although there is no known exploit code in common databases like Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion with 10 mentions, suggesting ongoing interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.00CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* | ||
11.4CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.4:*:*:*:*:*:*:* | ||
11.11CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.