User Account Enumeration in One-Time Passwords In Everything (OPIE) 2.32 and 2.4

User Account Enumeration in One-Time Passwords In Everything (OPIE) 2.32 and 2.4

CVE-2001-1483 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.

Learn more about our User Device Pen Test.