CVE-2004-2107 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.7% (pctl 94)
Patch early
A public exploit exists.
Description
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.74% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| finjan software | surfingate |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Finjan SurfinGate 6.0/7.0 - FHTTP Restart Command Execution | 2004-01-23 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0929.html
- http://marc.info/?l=bugtraq&m=107487999406339&w=2
- http://marc.info/?l=bugtraq&m=107522480913629&w=2
- http://secunia.com/advisories/10714
- http://www.securityfocus.com/bid/9478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14934
- http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0929.html
- http://marc.info/?l=bugtraq&m=107487999406339&w=2
- http://marc.info/?l=bugtraq&m=107522480913629&w=2
- http://secunia.com/advisories/10714
- http://www.securityfocus.com/bid/9478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14934
→ the Explorer · watch your stack · NVD