SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-1999-0856

login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.

MEDIUM 5.0EPSS 1.04%

Does this matter?

Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.

Description

login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.04% probability · 62th percentile
CISA KEV
Not listed
Affected
slackware/slackware linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.