- Description
- One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.
- Source
- cve@mitre.org
- NVD status
- Analyzed
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- nvd@nist.gov
- CWE-203
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nrl.navy:one-time_passwords_in_everything:2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30EBC335-4A60-4049-ACE6-43A5EF24ADB8"
},
{
"criteria": "cpe:2.3:a:nrl.navy:one-time_passwords_in_everything:2.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B142FD11-18C8-4BF3-AC54-8F9563BDA558"
}
],
"operator": "OR"
}
]
}
]