CVE-2001-1528 describes an information leakage vulnerability in the AmTote International homebet program. Attackers can differentiate between invalid account numbers and incorrect PINs based on distinct error messages, enabling brute-force attacks to identify valid account numbers. With a CVSS score of 5.0 (Medium), this vulnerability is remotely exploitable with low attack complexity, potentially leading to unauthorized disclosure of account existence. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-21116) exists for an account information brute-force attack, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:amtote:homebet:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.