CVE-2001-1354: Medium severity Netwin DMail vulnerability
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1354?
CVE-2001-1354 is considered a moderate severity vulnerability due to its weak password hashing implementation.
How do I fix CVE-2001-1354?
To fix CVE-2001-1354, upgrade to a version of NetWin software that utilizes stronger password hashing algorithms.
Which software is affected by CVE-2001-1354?
CVE-2001-1354 affects NetWin Authentication module versions 2.0 and 3.0b, as well as related packages like SurgeFTP and DMail.
What are the implications of CVE-2001-1354?
The implications of CVE-2001-1354 include the possibility for local users to decrypt passwords or exploit hashes due to weak password hashing.
Is CVE-2001-1354 still a concern today?
Yes, CVE-2001-1354 remains a concern for systems running older versions of affected software, as they may be susceptible to password compromise.