CVE Vulnerabilities

CVE-2001-1354

Published: Jul 20, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

Affected Software

NameVendorStart VersionEnd Version
DmailNetwin2.5d (including)2.5d (including)
DmailNetwin2.7 (including)2.7 (including)
DmailNetwin2.7q (including)2.7q (including)
DmailNetwin2.7r (including)2.7r (including)
DmailNetwin2.8e (including)2.8e (including)
DmailNetwin2.8f (including)2.8f (including)
DmailNetwin2.8g (including)2.8g (including)
DmailNetwin2.8h (including)2.8h (including)
DmailNetwin2.8i (including)2.8i (including)
SurgeftpNetwin1.0b (including)1.0b (including)
SurgeftpNetwin2.0a (including)2.0a (including)
SurgeftpNetwin2.0b (including)2.0b (including)

References