Pwgen Project maintains a specialized password-generation utility with a focused vulnerability footprint centered on its core pwgen product. The observed weakness involves improper restriction of excessive authentication attempts, reflecting constraints in the tool's credential-handling mechanism; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pwgen Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4441CRITICAL The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack. | Jan 27, 2020 | 9.8 | 26 | NO | NO |
CVE-2013-4440MEDIUM Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack. | Dec 19, 2014 | 5.0 | 20 | NO | NO |
CVE-2013-4442MEDIUM Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the n | Dec 19, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pwgen Project.
Media articles that mention a CVE ID that affects a product developed by Pwgen Project — matched by CVE ID, not by vendor name.