PT-2001-2119 · Knox · Knox Arkeia Server
Published
2001-08-31
·
Updated
2024-02-14
·
CVE-2001-0967
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Knox Arkeia server version 4.2
Description
The issue is related to the use of a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
Recommendations
For Knox Arkeia server version 4.2, consider updating the password encryption mechanism to use a unique salt for each user to prevent brute force attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knox Arkeia Server