CVE-2001-1463: High severity solarwinds serv-u file server vulnerability
Published Nov 19, 2001
·Updated
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
Affected Software
2 affected components
SolarWinds Serv-u File Server=3.0.0.16
SolarWinds Serv-u File Server=3.0.0.17
Event History
Nov 19, 2001
CVE Published
05:00 AM
Apr 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1463?
CVE-2001-1463 is classified as a high severity vulnerability due to the exposure of user passwords in plaintext.
2
How do I fix CVE-2001-1463?
To mitigate CVE-2001-1463, upgrade to a version of RhinoSoft Serv-U that does not transmit passwords in plaintext.
3
What versions of RhinoSoft Serv-U are affected by CVE-2001-1463?
CVE-2001-1463 affects RhinoSoft Serv-U versions 3.0.0.16 and 3.0.0.17.
4
What type of attack does CVE-2001-1463 enable?
CVE-2001-1463 enables attackers to sniff user passwords through unsecured transmission during the remote administration process.
5
Does enabling S/KEY One-Time Password authentication prevent CVE-2001-1463?
No, enabling S/KEY One-Time Password does not prevent CVE-2001-1463 as the passwords are still sent in plaintext.