CVE-2000-1008

PalmOS < 3.5.2 - Weak Password Encryption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-1008. PoCs published by @stake.

AI-analyzed exploit summary The exploit describes a weakness in Palm OS's password encryption scheme, allowing decryption of stored passwords in the 'Unsaved Preferences' database. Physical access to the device is required to extract and decrypt the password block.

Description

PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.

Exploits (1)

exploitdb WRITEUP VERIFIED
by @stake · textlocalpalm_os
https://www.exploit-db.com/exploits/20241

The exploit describes a weakness in Palm OS's password encryption scheme, allowing decryption of stored passwords in the 'Unsaved Preferences' database. Physical access to the device is required to extract and decrypt the password block.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Palm OS (versions with password protection feature)
No auth needed
Prerequisites: Physical access to the Palm device
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1715
Exploit, Patch, Vendor Advisory vendor-advisory x_refsource_atstake
http://www.atstake.com/research/advisories/2000/a092600-1.txt

Scores

EPSS 0.0054
EPSS Percentile 42.5%

Details

Status published
Products (1)
palm/palm_os < 3.5.2
Published Dec 11, 2000
Tracked Since Feb 18, 2026