5
CVSSv2

CVE-2001-1483

Published: 31/12/2001 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote malicious users to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

Vulnerable Product Search on Vulmon Subscribe to Product

nrl.navy one-time passwords in everything 2.32

nrl.navy one-time passwords in everything 2.4

Vendor Advisories

Debian Bug report logs - #436571 openssh: CVE-2007-2768 and CVE-2007-2243 (determine the existence of user accounts) Package: openssh; Maintainer for openssh is Debian OpenSSH Maintainers <debian-ssh@listsdebianorg>; Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Wed, 8 Aug 2007 09:30:02 UTC Seve ...