CVE-2000-1173 describes a data exposure vulnerability in Microsys CyberPatrol versions 4.003 and 4.005. The software uses weak encryption for credit card numbers and no encryption for other registration data, allowing attackers to intercept sensitive information via network sniffing. Rated Medium severity (CVSS 5.0), this vulnerability requires no authentication and has low attack complexity, posing a risk of confidential data disclosure. While not actively exploited in the wild or on CISA's KEV catalog, an exploit (EDB-20425) exists, though there is no evidence of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.04.003CPE matchmatch criteria | cpe:2.3:a:microsys:cyberpatrol:4.04.003:*:*:*:*:*:*:* | ||
4.04.005CPE matchmatch criteria | cpe:2.3:a:microsys:cyberpatrol:4.04.005:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.