First published: Mon Sep 03 2001(Updated: )
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =10.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0978 is considered a medium-risk vulnerability due to its potential for facilitating brute force password guessing attacks.
To mitigate CVE-2001-0978, consider auditing login practices and implementing rate limiting or account lockout mechanisms.
CVE-2001-0978 specifically affects HP-UX version 10.26.
Yes, CVE-2001-0978 could enable attackers to gain unauthorized access through undetected brute force password attempts.
CVE-2001-0978 can be exploited for brute force password guessing attacks due to the lack of failed login attempt logging.