Unrated severityNVD Advisory· Published Jul 20, 2001· Updated Apr 16, 2026
CVE-2001-1354
CVE-2001-1354
Description
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
Affected products
12cpe:2.3:a:netwin:dmail:2.5d:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:netwin:dmail:2.5d:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.7:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.7q:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.7r:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.8e:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.8f:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.8g:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.8h:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:dmail:2.8i:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/3075nvdExploitVendor Advisory
- online.securityfocus.com/archive/1/198293nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/6866nvd
News mentions
0No linked articles in our index yet.