Vulnerability record · CVE-2004-0627 · published 6 December 2004
CVE-2004-0627: MySQL authentication bypass via zero-length scrambled string
Mysql · Mysql
The check_scramble_323 function in MySQL 4.1.x before 4.1.3 and 5.0 fails to properly validate a zero-length scrambled authentication string, allowing an attacker to bypass authentication. Because the flaw sits in the core authentication handshake, any reachable MySQL service on an affected version is at risk.
Description
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote authentication bypass with a CVSS 2.0 score of 10 and very high EPSS probability, though the affected versions are long obsolete.
What it is
The check_scramble_323 function in MySQL 4.1.x before 4.1.3 and 5.0 fails to properly validate a zero-length scrambled authentication string, allowing an attacker to bypass authentication. Because the flaw sits in the core authentication handshake, any reachable MySQL service on an affected version is at risk.
Impact
An attacker gains full access to the MySQL server without valid credentials, with the CVSS 2.0 vector indicating complete compromise of confidentiality, integrity and availability. This can expose or destroy all hosted data and potentially allow further host-level abuse.
Attack surface
Reachable over the network via the MySQL protocol (AV:N, AC:L, Au:N); no authentication is required and no user interaction is involved. Any client able to open a connection to the database port can attempt the bypass.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is very high (0.696 probability, 99.3rd percentile), indicating strong likelihood of attempted exploitation. Reference tags are limited to Patch, Vendor Advisory, Third Party Advisory and US Government Resource.
What to do
- Upgrade MySQL to 4.1.3 or later, or to a current supported release; the vendor advisory and CERT/CC note describe the fix.
- If immediate upgrade is impossible, restrict network access to the MySQL port to trusted hosts only and block external exposure.
- Enforce strong authentication and least-privilege database accounts so a bypass yields minimal useful access.
- Monitor vendor and CERT/CC advisories for backported fixes if you run a downstream distribution build.
Detection
- Review MySQL connection and error logs for authentication attempts using empty or malformed scramble strings.
- Alert on successful logins from unexpected source IPs or accounts that should not authenticate remotely.
- Baseline normal client versions and flag connections from unusual or outdated MySQL client libraries.
- Correlate database access spikes or schema changes with authentication events to catch post-bypass activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0001.html | PatchVendor Advisory |
| http://marc.info/?l=bugtraq&m=108904917528205&w=2 | |
| http://www.kb.cert.org/vuls/id/184030 | PatchThird Party AdvisoryUS Government Resource |
| http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0001.html | PatchVendor Advisory |
| http://marc.info/?l=bugtraq&m=108904917528205&w=2 | |
| http://www.kb.cert.org/vuls/id/184030 | PatchThird Party AdvisoryUS Government Resource |
Track CVE-2004-0627 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.