PT-2001-1795 · Zetetic · Zetetic Strip
Publicado
2001-07-27
·
Atualizado
2017-12-19
·
CVE-2001-0597
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Zetetic Secure Tool for Recalling Important Passwords (STRIP) versions 0.5 and earlier
Description:
The issue allows a local attacker to recover passwords via a brute force attack due to the use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw that reduces the password 'search space'.
Recommendations:
For versions 0.5 and earlier, consider implementing additional security measures to protect against brute force attacks, such as limiting the number of login attempts or using a more secure random number generator. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zetetic Strip