PT-2001-2119 · Knox · Knox Arkeia Server
CVE-2001-0967
·
Publicado
2001-08-31
·
Atualizado
2024-02-14
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Knox Arkeia server version 4.2
Description
The issue is related to the use of a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
Recommendations
For Knox Arkeia server version 4.2, consider updating the password encryption mechanism to use a unique salt for each user to prevent brute force attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Knox Arkeia Server