peter bassill · operator
$ cve CVE-2004-2107 JSON

CVE-2004-2107 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.7% (pctl 94)

Patch early

A public exploit exists.

Description

Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.74% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
finjan softwaresurfingate

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD