Lucene search

K
jvnJapan Vulnerability NotesJVN:19445002
HistoryApr 19, 2007 - 12:00 a.m.

JVN#19445002 APOP password recovery vulnerability

2007-04-1900:00:00
Japan Vulnerability Notes
jvn.jp
31

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.088

Percentile

94.6%

Impact

APOP passwords may be compromised. When the same password is used for other systems, those systems could be compromised as well.

Solution

Products Affected

  • Mail clients with an APOP implementation
    As this is a protocol issue, software fixes cannot solve the issue essentially. Encrypted communications such as POP over SSL are recommended. Moreover, users should use different passwords for different services or accounts to minimize the risk of their accounts to be compromised.

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

EPSS

0.088

Percentile

94.6%