PT-2001-2156 · Starfish · Starfish Truesync Desktop

Published

2001-08-31

·

Updated

2008-09-05

·

CVE-2001-1007

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Starfish Truesync Desktop version 2.0b
Description The issue allows attackers to quickly guess the device key via a brute force attack due to the small keyspace used for device keys and the lack of a delay when an incorrect key is entered.
Recommendations For version 2.0b, consider implementing a delay after a specified number of incorrect key entries to slow down brute force attacks, and increase the keyspace for device keys to make guessing more difficult. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1007

Affected Products

Starfish Truesync Desktop