SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-1483

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

MEDIUM 5.0EPSS 3.67%

Does this matter?

Lower severity and a low EPSS score (3.67%). Track it; it rarely justifies an emergency change on its own.

Description

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.67% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
nrl.navy/one-time passwords in everything
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.