PT-2001-2156 · Starfish · Starfish Truesync Desktop

Publicado

2001-08-31

·

Atualizado

2008-09-05

·

CVE-2001-1007

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Starfish Truesync Desktop version 2.0b
Description The issue allows attackers to quickly guess the device key via a brute force attack due to the small keyspace used for device keys and the lack of a delay when an incorrect key is entered.
Recommendations For version 2.0b, consider implementing a delay after a specified number of incorrect key entries to slow down brute force attacks, and increase the keyspace for device keys to make guessing more difficult. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1007

Produtos afetados

Starfish Truesync Desktop