SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-1528

AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.

MEDIUM 5.0EPSS 7.91%

Does this matter?

Lower severity and a low EPSS score (7.91%). Track it; it rarely justifies an emergency change on its own.

Description

AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.91% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
amtote/homebet
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.