CVE-2000-0559: Weak Encryption
Published Jun 7, 2000
·Updated
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.
Affected Software
1 affected component
Broadcom Etrust Intrusion Detection<=1.4.1.13
Remediation
Patch Available
Event History
Jun 7, 2000
CVE Published
04:00 AM
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0559?
CVE-2000-0559 is considered a high severity vulnerability due to the weak encryption of administrative passwords.
2
How do I fix CVE-2000-0559?
To fix CVE-2000-0559, update the eTrust Intrusion Detection System to a version higher than 1.4.1.13 that addresses this encryption issue.
3
What software is affected by CVE-2000-0559?
CVE-2000-0559 affects Broadcom eTrust Intrusion Detection versions up to and including 1.4.1.13.
4
What type of encryption vulnerability is described in CVE-2000-0559?
CVE-2000-0559 describes a vulnerability where weak XOR encryption is used to store passwords.
5
Can local users exploit CVE-2000-0559?
Yes, local users can exploit CVE-2000-0559 to easily decrypt administrative passwords stored in the registry.