First published: Mon Dec 31 2001(Updated: )
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nrl Opie | =2.32 | |
Nrl Opie | =2.4 | |
Nrl.navy One-time Passwords In Everything | =2.4 | |
Nrl.navy One-time Passwords In Everything | =2.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1483 is considered a medium severity vulnerability due to the potential for remote attackers to enumerate user accounts.
To fix CVE-2001-1483, upgrade to OPIE version 2.4 or later where this vulnerability is addressed.
The affected versions for CVE-2001-1483 are OPIE 2.32 and 2.4.
CVE-2001-1483 can be exploited by remote attackers to discover valid user accounts on the system.
The impact of CVE-2001-1483 on security is that it allows unauthorized users to identify valid user accounts, which can aid in further attacks.