← back
CVE-2001-0597

CVE-2001-0597

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.1%
from disclosure to weapon0 days
Published on NVDJul 27
1st PoCApr 10
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password 'search space'.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.