CVE-2004-2314: High severity Novell iChain vulnerability
Published Dec 31, 2004
·Updated
The Telnet listener for Novell iChain Server before 2.2 Field Patch 3b 2.2.116 does not have a password by default, which allows remote attackers to gain access.
Affected Software
1 affected component
Novell iChain<=2.2
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2314?
CVE-2004-2314 is considered a critical vulnerability because it allows remote attackers to gain unauthorized access without a password.
2
How do I fix CVE-2004-2314?
To fix CVE-2004-2314, update to Novell iChain Server version 2.2 Field Patch 3b or later.
3
What type of software is affected by CVE-2004-2314?
CVE-2004-2314 affects Novell iChain Server versions before 2.2 Field Patch 3b.
4
Can CVE-2004-2314 be exploited remotely?
Yes, CVE-2004-2314 can be exploited remotely by attackers due to the lack of a default password.
5
Is there a workaround for CVE-2004-2314 if I cannot update my software?
As a workaround for CVE-2004-2314, consider disabling the Telnet service or applying access control measures where possible.