CVE-2001-0967: Critical severity knox software arkeia vulnerability
Published Aug 31, 2001
·Updated
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
Affected Software
4 affected components
Knox Software Arkeia=4.2
Knox Software Arkeia=4.2.8.2
Arkeia Arkeia=4.2
Arkeia Arkeia=4.2.8-2
Remediation
Patch Available
Event History
Aug 31, 2001
CVE Published
04:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0967?
CVE-2001-0967 is considered to have a high severity due to the potential for brute force password attacks.
2
How do I fix CVE-2001-0967?
To fix CVE-2001-0967, upgrade to a version of Knox Arkeia that does not use a constant salt for password encryption.
3
Which versions of Arkeia are affected by CVE-2001-0967?
CVE-2001-0967 affects Knox Arkeia server version 4.2 and possibly other versions, including 4.2.8-2.
4
What type of vulnerability is CVE-2001-0967?
CVE-2001-0967 is a password vulnerability that exploits weak encryption practices with the crypt() function.
5
Can CVE-2001-0967 be exploited remotely?
Yes, CVE-2001-0967 can be exploited remotely if an attacker can obtain password hashes.