CVE-2001-1169
Last modified
CVE-2001-1169 is a vulnerability of currently unknown severity. keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bell Communications Research | S Key | gold |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-08/0441.htmlPatch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2001-08/0441.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1169?
How severe is CVE-2001-1169?
How do I fix CVE-2001-1169?
Are you affected by CVE-2001-1169?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
