CVE-2011-2190 — Cherokee vulnerability
Severity
2.1LOWNVD
EPSS
0.1%
top 75.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 7
Latest updateMay 17
Description
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.
CVSS vector
AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
2💬Community
3Bugzilla▶
CVE-2011-2190 cherokee: A weakness in Cherokee's administrative interface random administrator password generation↗2011-06-03