CVE-2014-0984
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry...
- Published
- Apr 17, 2014
- Updated
- Aug 6, 2024
- Assigning CNA
- mitre
- Evidence observed
- Apr 17, 2014
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:NLow · next 30 days
- Percentile
- 85.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain passwords via a brute-force attack that relies on timing differences in responses to incorrect password guesses, aka a timing side-channel attack.
Sources
1Core Security · hardware · Apr 17, 2014
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.