Vulnerabilities > Use of Password Hash With Insufficient Computational Effort

DATE CVE VULNERABILITY TITLE RISK
2021-03-17 CVE-2020-28873 Use of Password Hash With Insufficient Computational Effort vulnerability in Fluxbb 1.5.11
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form.
network
low complexity
fluxbb CWE-916
7.5
2021-01-26 CVE-2020-6780 Use of Password Hash With Insufficient Computational Effort vulnerability in Bosch Fsm-2500 Firmware and Fsm-5000 Firmware
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.
network
low complexity
bosch CWE-916
4.0
2021-01-21 CVE-2021-21253 Use of Password Hash With Insufficient Computational Effort vulnerability in Onlinevotingsystem Project Onlinevotingsystem 1.1.1
OnlineVotingSystem is an open source project hosted on GitHub.
network
low complexity
onlinevotingsystem-project CWE-916
5.3
2020-11-17 CVE-2020-14389 Use of Password Hash With Insufficient Computational Effort vulnerability in Redhat Keycloak
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
network
low complexity
redhat CWE-916
8.1
2020-11-09 CVE-2020-27693 Use of Password Hash With Insufficient Computational Effort vulnerability in Trendmicro Interscan Messaging Security Virtual Appliance 8.5.1.1516/9.0/9.1
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
local
low complexity
trendmicro CWE-916
2.1
2020-10-16 CVE-2019-12305 Use of Password Hash With Insufficient Computational Effort vulnerability in Actions-Micro Ezcast PRO II Firmware
In EZCast Pro II, the administrator password md5 hash is provided upon a web request.
low complexity
actions-micro CWE-916
3.3
2020-08-25 CVE-2020-14512 Use of Password Hash With Insufficient Computational Effort vulnerability in Secomea Gatemanager 8250 Firmware
GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.
network
low complexity
secomea CWE-916
5.0
2020-07-14 CVE-2020-10040 Use of Password Hash With Insufficient Computational Effort vulnerability in Siemens products
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18).
local
low complexity
siemens CWE-916
2.1
2020-06-19 CVE-2017-18917 Use of Password Hash With Insufficient Computational Effort vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7.
5.0
2020-06-15 CVE-2020-0533 Use of Password Hash With Insufficient Computational Effort vulnerability in Intel Converged Security Management Engine Firmware
Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
local
low complexity
intel CWE-916
4.6