HomeIeeeCVE-2004-1038

CVE-2004-1038

UNKNOWN
7.2CVSS
Published: 2005-03-01
Updated: 2025-04-03
AI Analysis

Description

A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degrees of physical access to exploit. NOTE: this was reported in 2008 to affect Windows Vista, but some Linux-based operating systems have protection mechanisms against this attack.

CVSS Metrics

Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector
local
Access Cmplx
low
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
IEEE
Published
3/1/2005
Last Modified
4/3/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

ieee : firewire_ieee

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2004-1038 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com