omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-05-06T11:45:16

Updated: 2024-08-03T22:55:53.471Z

Reserved: 2021-04-15T00:00:00

Link: CVE-2021-31245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-06T13:15:12.607

Modified: 2024-11-21T06:05:21.670

Link: CVE-2021-31245

cve-icon Redhat

No data.