← Vulnerability feed

Vulnerability record · CVE-2004-0627 · published 6 December 2004

CVE-2004-0627: MySQL authentication bypass via zero-length scrambled string

Mysql · Mysql

The check_scramble_323 function in MySQL 4.1.x before 4.1.3 and 5.0 fails to properly validate a zero-length scrambled authentication string, allowing an attacker to bypass authentication. Because the flaw sits in the core authentication handshake, any reachable MySQL service on an affected version is at risk.

10.0 CVSS 2.0 High EPSS 70% · top 0.7%
10.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote authentication bypass with a CVSS 2.0 score of 10 and very high EPSS probability, though the affected versions are long obsolete.

What it is

The check_scramble_323 function in MySQL 4.1.x before 4.1.3 and 5.0 fails to properly validate a zero-length scrambled authentication string, allowing an attacker to bypass authentication. Because the flaw sits in the core authentication handshake, any reachable MySQL service on an affected version is at risk.

Impact

An attacker gains full access to the MySQL server without valid credentials, with the CVSS 2.0 vector indicating complete compromise of confidentiality, integrity and availability. This can expose or destroy all hosted data and potentially allow further host-level abuse.

Attack surface

Reachable over the network via the MySQL protocol (AV:N, AC:L, Au:N); no authentication is required and no user interaction is involved. Any client able to open a connection to the database port can attempt the bypass.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is very high (0.696 probability, 99.3rd percentile), indicating strong likelihood of attempted exploitation. Reference tags are limited to Patch, Vendor Advisory, Third Party Advisory and US Government Resource.

What to do

  • Upgrade MySQL to 4.1.3 or later, or to a current supported release; the vendor advisory and CERT/CC note describe the fix.
  • If immediate upgrade is impossible, restrict network access to the MySQL port to trusted hosts only and block external exposure.
  • Enforce strong authentication and least-privilege database accounts so a bypass yields minimal useful access.
  • Monitor vendor and CERT/CC advisories for backported fixes if you run a downstream distribution build.

Detection

  • Review MySQL connection and error logs for authentication attempts using empty or malformed scramble strings.
  • Alert on successful logins from unexpected source IPs or accounts that should not authenticate remotely.
  • Baseline normal client versions and flag connections from unusual or outdated MySQL client libraries.
  • Correlate database access spikes or schema changes with authentication events to catch post-bypass activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0627 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0628Mysql vulnerabilityStack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute a…EPSS 7.8%9.0CVE-2003-0780MySQL get_salt_from_password buffer overflow allows code executionMySQL 4.0.14 and earlier, plus 3.23.x, contain a buffer overflow in get_salt_from_password in sql_acl.cc. An attacker with ALTER TABLE privileges can…EPSS 78%analysed8.5CVE-2009-2446Mysql vulnerabilityMultiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remot…EPSS 11%7.8CVE-2017-15945Mariadb incorrect permission assignment vulnerabilityThe installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages …EPSS 0.37%7.5CVE-2012-0553Mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulner…EPSS 2.6%7.5CVE-2013-1492Mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulner…EPSS 2.8%7.5CVE-2012-0882Oracle mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote at…EPSS 5.3%7.5CVE-2008-0226yaSSL buffer overflows in handshake and input parsingyaSSL 1.7.5 and earlier contains multiple buffer overflows in the ProcessOldClientHello function (handshake.cpp) and the "input_buffer& operator>>" r…EPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0627), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.