Lucene search

K
cveMitreCVE-2001-1483
HistoryJun 21, 2005 - 4:00 a.m.

CVE-2001-1483

2005-06-2104:00:00
CWE-203
mitre
web.nvd.nist.gov
31
cve-2001-1483
opie 2.32
opie 2.4
account identification
passphrase printout
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

59.5%

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

Affected configurations

Nvd
Node
nrl.navyone-time_passwords_in_everythingMatch2.4
OR
nrl.navyone-time_passwords_in_everythingMatch2.32
VendorProductVersionCPE
nrl.navyone-time_passwords_in_everything2.4cpe:2.3:a:nrl.navy:one-time_passwords_in_everything:2.4:*:*:*:*:*:*:*
nrl.navyone-time_passwords_in_everything2.32cpe:2.3:a:nrl.navy:one-time_passwords_in_everything:2.32:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

59.5%