Vulnerability Name:

CVE-2004-2421 (CCN-17074)

Assigned:2004-08-23
Published:2004-08-23
Updated:2017-07-11
Summary:Unknown vulnerability in Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7, when running on HP-UX in trusted mode, allows attackers to bypass authentication and gain administrator rights.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2004-2421

Source: CCN
Type: SA12050
Hitachi JP1/File Transmission Server/FTP Two Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
12050

Source: CCN
Type: SECTRACK ID: 1011023
Hitachi Job Management Partner (JP1) Authentication Flaw Has Unspecified Impact

Source: SECTRACK
Type: Patch
1011023

Source: CCN
Type: Hitachi Support Web site
Solution for JP1/File Transmission Server/FTP

Source: CCN
Type: Hitachi Vulnerability Information HS04-004-01
Issue in Log-In Authentication of JP1/File Transmission Server/FTP

Source: CONFIRM
Type: UNKNOWN
http://www.hitachi-support.com/security_e/vuls_e/HS04-004_e/index-e.html

Source: CCN
Type: OSVDB ID: 9132
Hitachi JP1/File Transmission Server/FTP Login Unspecified

Source: BID
Type: UNKNOWN
11012

Source: CCN
Type: BID-11012
Hitachi Job Management Partner 1 Multiple Remote Vulnerabilities

Source: XF
Type: UNKNOWN
hitachi-jp1ftp-authentication(17074)

Source: XF
Type: UNKNOWN
hitachi-jp1ftp-authentication(17074)

Vulnerable Configuration:Configuration 1:
  • cpe:/h:hitachi:jp1_p-1b41-9461:06_00_h:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1b41-9461:06_01_d:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1b41-9461:06_02-b:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1b41-9461:06_02_c:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1b41-9471:07_00_a:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1b41-9471:07_10:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1b41-9471:07_10_a:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1j41-9471:07_00:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1j41-9471:07_10:*:*:*:*:*:*:*
  • OR cpe:/h:hitachi:jp1_p-1j41-9471:07_10_a:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:hp:hp-ux:10.20:*:*:*:*:*:*:*
  • AND
  • cpe:/o:hp:hp-ux:11:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    hitachi jp1 p-1b41-9461 06_00_h
    hitachi jp1 p-1b41-9461 06_01_d
    hitachi jp1 p-1b41-9461 06_02-b
    hitachi jp1 p-1b41-9461 06_02_c
    hitachi jp1 p-1b41-9471 07_00_a
    hitachi jp1 p-1b41-9471 07_10
    hitachi jp1 p-1b41-9471 07_10_a
    hitachi jp1 p-1j41-9471 07_00
    hitachi jp1 p-1j41-9471 07_10
    hitachi jp1 p-1j41-9471 07_10_a
    hp hp-ux 10.20
    hp hp-ux 11