HIGH
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo
Published Mar 15, 2002
7.5
HIGHCVSS 2.0
EPSS 1.19%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.