CVE-2001-1354
NetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password Encryption
Severity Score
4.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2001-07-20 CVE Published
- 2001-07-20 First Exploit
- 2002-06-07 CVE Reserved
- 2023-03-08 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6866 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/21020 | 2001-07-20 | |
http://www.securityfocus.com/bid/3075 | 2024-08-08 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://online.securityfocus.com/archive/1/198293 | 2017-12-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.5d Search vendor "Netwin" for product "Dmail" and version "2.5d" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.7 Search vendor "Netwin" for product "Dmail" and version "2.7" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.7q Search vendor "Netwin" for product "Dmail" and version "2.7q" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.7r Search vendor "Netwin" for product "Dmail" and version "2.7r" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.8e Search vendor "Netwin" for product "Dmail" and version "2.8e" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.8f Search vendor "Netwin" for product "Dmail" and version "2.8f" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.8g Search vendor "Netwin" for product "Dmail" and version "2.8g" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.8h Search vendor "Netwin" for product "Dmail" and version "2.8h" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Dmail Search vendor "Netwin" for product "Dmail" | 2.8i Search vendor "Netwin" for product "Dmail" and version "2.8i" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Surgeftp Search vendor "Netwin" for product "Surgeftp" | 1.0b Search vendor "Netwin" for product "Surgeftp" and version "1.0b" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Surgeftp Search vendor "Netwin" for product "Surgeftp" | 2.0a Search vendor "Netwin" for product "Surgeftp" and version "2.0a" | - |
Affected
| ||||||
Netwin Search vendor "Netwin" | Surgeftp Search vendor "Netwin" for product "Surgeftp" | 2.0b Search vendor "Netwin" for product "Surgeftp" and version "2.0b" | - |
Affected
|