PT-2021-19214 · Unknown · Openmptcprouter-Vps-Admin

Published

2021-05-06

·

Updated

2021-05-13

·

CVE-2021-31245

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions openmptcprouter-vps-admin versions 0.57.3 and earlier
Description The issue allows remote attackers to guess the password via a timing attack because the password comparison is done in a length-dependent manner. This means that the time it takes to compare the user-provided password with the original password can give away information about the length of the correct password, making it easier for attackers to guess it.
Recommendations For openmptcprouter-vps-admin versions 0.57.3 and earlier, consider updating to a newer version that fixes this issue, as the current version allows for a timing attack due to the length-dependent password comparison. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31245

Affected Products

Openmptcprouter-Vps-Admin