CVE-1999-1073

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published Nov 30, 1998
Updated: Nov 20, 2024

Summary

CVE-1999-1073 is a vulnerability affecting Excite for Web Servers (EWS) version 1.1. This issue arises due to the server's practice of recording the first two characters of plaintext passwords at the beginning of encrypted passwords. An attacker can take advantage of this quirk to streamline brute force or dictionary attacks, making it easier to guess passwords. This flaw poses a significant risk to system security, as weak passwords are easier to crack. Users are advised to upgrade their EWS servers or apply patches provided by the vendor to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share