{"api_version":"1","generated_at":"2026-07-23T04:35:15+00:00","cve":"CVE-2001-1467","urls":{"html":"https://cve.report/CVE-2001-1467","api":"https://cve.report/api/cve/CVE-2001-1467.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1467","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1467"},"summary":{"title":"CVE-2001-1467","description":"mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-04-11 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html","name":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - Re: flaw in RH ``mkpasswd'' command (importance of seeds & algorithms) - From peterw@USA.NET","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html","name":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - flaw in RH ``mkpasswd'' command - From shez@MOLIONS.COM","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6382","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6382","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/2632","name":"http://www.securityfocus.com/bid/2632","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Expect mkpasswd Biased Random Number Generation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/527736","name":"http://www.kb.cert.org/vuls/id/527736","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#527736","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1001303","name":"http://securitytracker.com/id?1001303","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - The Expect Mkpasswd Utility Generates a Relatively Small Number of Passwords, Making Brute Force Password Guessing Attempts Easier","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1467","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1467","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1467","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"don_libes","cpe5":"expect","cpe6":"5.2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:58:11.593Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20010411 flaw in RH ``mkpasswd'' command","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html"},{"name":"mkpasswd-weak-passwords(6382)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6382"},{"name":"VU#527736","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/527736"},{"name":"1001303","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1001303"},{"name":"2632","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/2632"},{"name":"20010412 Re: flaw in RH ``mkpasswd'' command (importance of seeds & algorithms)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-04-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20010411 flaw in RH ``mkpasswd'' command","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html"},{"name":"mkpasswd-weak-passwords(6382)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6382"},{"name":"VU#527736","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/527736"},{"name":"1001303","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1001303"},{"name":"2632","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/2632"},{"name":"20010412 Re: flaw in RH ``mkpasswd'' command (importance of seeds & algorithms)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1467","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20010411 flaw in RH ``mkpasswd'' command","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html"},{"name":"mkpasswd-weak-passwords(6382)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6382"},{"name":"VU#527736","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/527736"},{"name":"1001303","refsource":"SECTRACK","url":"http://securitytracker.com/id?1001303"},{"name":"2632","refsource":"BID","url":"http://www.securityfocus.com/bid/2632"},{"name":"20010412 Re: flaw in RH ``mkpasswd'' command (importance of seeds & algorithms)","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1467","datePublished":"2005-04-21T04:00:00.000Z","dateReserved":"2005-04-21T00:00:00.000Z","dateUpdated":"2024-08-08T04:58:11.593Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-04-11 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:don_libes:expect:5.2.8:*:*:*:*:*:*:*","matchCriteriaId":"F981BF07-D0F3-48D8-88A9-ABD67ACE48E3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1467","Ordinal":"1","Title":"CVE-2001-1467","CVE":"CVE-2001-1467","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1467","Ordinal":"1","NoteData":"mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.","Type":"Description","Title":"CVE-2001-1467"},{"CveYear":"2001","CveId":"1467","Ordinal":"2","NoteData":"2005-04-21","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"1467","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}