Lucene search

K
cveMitreCVE-2001-0597
HistoryAug 02, 2001 - 4:00 a.m.

CVE-2001-0597

2001-08-0204:00:00
mitre
web.nvd.nist.gov
34
cve-2001-0597
zetetic
strip 0.5
palmos
brute force attack
password security
sysrandom
timegetticks

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

High

EPSS

0

Percentile

0.4%

Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP’s use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password ‘search space’.

Affected configurations

Nvd
Node
zetetic_enterprisesstripRange0.5
OR
zetetic_enterprisesstripMatch0.3
OR
zetetic_enterprisesstripMatch0.4
VendorProductVersionCPE
zetetic_enterprisesstrip*cpe:2.3:a:zetetic_enterprises:strip:*:*:*:*:*:*:*:*
zetetic_enterprisesstrip0.3cpe:2.3:a:zetetic_enterprises:strip:0.3:*:*:*:*:*:*:*
zetetic_enterprisesstrip0.4cpe:2.3:a:zetetic_enterprises:strip:0.4:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

High

EPSS

0

Percentile

0.4%

Related for CVE-2001-0597