CVE-2001-0967

CRITICAL

Knox Arkeia server <4.2 - Info Disclosure

Title source: llm

Description

Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.

Scores

CVSS v3 9.8
EPSS 0.0036
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-916
Status draft

Affected Products (2)

arkeia/arkeia
arkeia/arkeia

Timeline

Published Aug 31, 2001
Tracked Since Feb 18, 2026