VulnerabilityModified
CVE-2001-1528
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
MEDIUM 5.0EPSS 7.91%
Does this matter?
Lower severity and a low EPSS score (7.91%). Track it; it rarely justifies an emergency change on its own.
Description
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.91% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- amtote/homebet
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.htmlBroken Link, Vendor Advisory
- http://www.iss.net/security_center/static/7185.phpBroken Link
- http://www.securityfocus.com/bid/3371Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.htmlBroken Link, Vendor Advisory
- http://www.iss.net/security_center/static/7185.phpBroken Link
- http://www.securityfocus.com/bid/3371Broken Link, Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.