VulnerabilityModified
CVE-2001-1436
Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.
MEDIUM 4.6EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Affected
- dallas semiconductor/ibutton
- Source
- cve@mitre.org
References
- http://www.atstake.com/research/advisories/2001/a011801-1.txtExploit, Vendor Advisory
- http://www.kb.cert.org/vuls/id/178560Exploit, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10625
- http://www.atstake.com/research/advisories/2001/a011801-1.txtExploit, Vendor Advisory
- http://www.kb.cert.org/vuls/id/178560Exploit, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10625
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.