MEDIUM · 4.6

CVE-2001-1354

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or us...

Vulnerability Description

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
NetwinDmail2.5d
NetwinSurgeftp1.0b

References

FAQ

What is CVE-2001-1354?

CVE-2001-1354 is a vulnerability with a CVSS score of 4.6 (MEDIUM). NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or us...

How severe is CVE-2001-1354?

CVE-2001-1354 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1354?

Check the references section above for vendor advisories and patch information. Affected products include: Netwin Dmail, Netwin Surgeftp.