Unrated severityNVD Advisory· Published Nov 19, 2001· Updated Apr 16, 2026
CVE-2001-1463
CVE-2001-1463
Description
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
Affected products
2cpe:2.3:a:solarwinds:serv-u_file_server:3.0.0.16:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:solarwinds:serv-u_file_server:3.0.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:serv-u_file_server:3.0.0.17:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- securitytracker.com/idnvdExploit
- www.kb.cert.org/vuls/id/279763nvdExploitUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/7925nvd
News mentions
0No linked articles in our index yet.