CVE-2004-2004 describes a critical vulnerability in the Live CD of SUSE LINUX 9.1 Personal edition, where the root account is configured without a password. This misconfiguration allows remote attackers to gain full administrative privileges via SSH. The vulnerability carries a maximum CVSS score of 10.0, indicating a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Its high FAUCET Risk Score of 93/100 further emphasizes its critical nature. Despite its age and severity, there is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. However, the CVE has garnered significant community discussion, with 20 mentions, suggesting ongoing awareness and interest among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1CPE matchmatch criteria | cpe:2.3:o:suse:suse_linux:9.1:*:personal:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.