CVE-2001-0978: High severity HPE HP-UX vulnerability
login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0978?
CVE-2001-0978 is considered a medium-risk vulnerability due to its potential for facilitating brute force password guessing attacks.
How do I fix CVE-2001-0978?
To mitigate CVE-2001-0978, consider auditing login practices and implementing rate limiting or account lockout mechanisms.
What software is affected by CVE-2001-0978?
CVE-2001-0978 specifically affects HP-UX version 10.26.
Can CVE-2001-0978 lead to unauthorized access?
Yes, CVE-2001-0978 could enable attackers to gain unauthorized access through undetected brute force password attempts.
What kind of attacks can exploit CVE-2001-0978?
CVE-2001-0978 can be exploited for brute force password guessing attacks due to the lack of failed login attempt logging.