Описание
omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.57.3 (включая)
cpe:2.3:a:openmptcprouter:openmptcprouter:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01342
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.
EPSS
Процентиль: 80%
0.01342
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-287