CVE-2001-1354
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value…
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Affected
- netwin/dmail · netwin/surgeftp
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/198293Vendor Advisory
- http://www.securityfocus.com/bid/3075Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6866
- http://online.securityfocus.com/archive/1/198293Vendor Advisory
- http://www.securityfocus.com/bid/3075Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6866
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.