NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
2001-07-20T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netwin | dmail | 2.5d | Yes |
Application | netwin | dmail | 2.7 | Yes |
Application | netwin | dmail | 2.7q | Yes |
Application | netwin | dmail | 2.7r | Yes |
Application | netwin | dmail | 2.8e | Yes |
Application | netwin | dmail | 2.8f | Yes |
Application | netwin | dmail | 2.8g | Yes |
Application | netwin | dmail | 2.8h | Yes |
Application | netwin | dmail | 2.8i | Yes |
Application | netwin | surgeftp | 1.0b | Yes |
Application | netwin | surgeftp | 2.0a | Yes |
Application | netwin | surgeftp | 2.0b | Yes |