CVE-2004-1052

CRITICAL

Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (e...

Affects 3 products across 3 vendors.

BCS7.62
CVSS 2.010.0
EPSS3.6%
Percentile88th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2005. A critical vulnerability affects Bnc systems (CVE-2004-1052). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2005-GLOBAL-008271-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-1052?
This vulnerability was disclosed in 2005. A critical vulnerability affects Bnc systems (CVE-2004-1052). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2004-1052?
CVE-2004-1052 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.6%.
Is CVE-2004-1052 actively exploited?
No confirmed active exploitation of CVE-2004-1052 as of 2026-05-30.
How do I remediate CVE-2004-1052?
Priority: MEDIUM. Advisory: http://www.securityfocus.com/bid/11647 PSIRT: [email protected]
What systems are affected by CVE-2004-1052?
CVE-2004-1052 affects: Bnc, Debian, Gentoo.
Vulnerability Details
CVE IDCVE-2004-1052
BSIDBS-2005-GLOBAL-008271-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2005-03-01
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Bnc Bnc
Debian Debian Linux
Gentoo Linux
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 7823 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hasha20d532ddff9a558aff1fdc8d296468805376238a1902e9a5e128950c6db52e09fc14be424e0b514421aeebc622f32cdd7cb154596b099b5eef189312eeb57a8
Related CVEs affecting Bnc
CVE-2004-1482 7.5 The sbuf_getmsg function in BNC incorrectly handles backspace characters, whi... CVE-2004-2612 7.5 BNC 2.9.0 only grants access when an incorrect password is provided, which al...
View all Bnc CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →