AOL Instant Messenger Password Encryption Weakness

Low Nessus Network Monitor Plugin ID 1259

Synopsis

The remote host passes information across the network in an insecure manner

Description

The remote host is running AOL Instant Messenger (AIM). Version 1.2 of AIM uses a very weak encryption scheme to protect user passwords. A remote attacker may determine a user's password given only the encrypted form of the password (by sniffing the login process for example).

Solution

Upgrade to the latest version of AOL Instant Messenger.

Plugin Details

Severity: Low

ID: 1259

File Name: 1259.prm

Published: 2004/08/20

Modified: 2016/02/05

Risk Information

Risk Factor: Low

CVSSv2

Base Score: 3.3

Temporal Score: 2.8

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:U/RL:U/RC:ND

CVSSv3

Base Score: 4.2

Temporal Score: 3.8

Vector: CVSS3#AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS3#E:U/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:aol:aim

Reference Information

BID: 6777