CVE-1999-1073
CVSS 2.0 Score 7.2 of 10 (high)
Details
Summary
CVE-1999-1073 is a vulnerability affecting Excite for Web Servers (EWS) version 1.1. This issue arises due to the server's practice of recording the first two characters of plaintext passwords at the beginning of encrypted passwords. An attacker can take advantage of this quirk to streamline brute force or dictionary attacks, making it easier to guess passwords. This flaw poses a significant risk to system security, as weak passwords are easier to crack. Users are advised to upgrade their EWS servers or apply patches provided by the vendor to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Excite Japan Co.,Ltd.