First published: Mon Apr 10 2000(Updated: )
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cryptocard Cryptoadmin | =4.1 | |
CRYPTOCard CryptoAdmin | =4.1 | |
=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0275 is considered a high severity vulnerability due to the weak encryption used to store PIN numbers.
To fix CVE-2000-0275, upgrade to a newer version of the CRYPTOCard CryptoAdmin software that employs stronger encryption methods.
An attacker can exploit CVE-2000-0275 to access the user's PIN and generate valid PT-1 tokens.
Users of CRYPTOCard CryptoAdmin version 4.1 for PalmOS are affected by CVE-2000-0275.
The impact of CVE-2000-0275 is that unauthorized users can gain access to secure systems by generating valid tokens after compromising a user's PIN.