Vulnerabilities > Use of Password Hash With Insufficient Computational Effort

DATE CVE VULNERABILITY TITLE RISK
2019-10-06 CVE-2019-17216 Use of Password Hash With Insufficient Computational Effort vulnerability in Vzug Combi-Stream Mslq Firmware Ethernetr07
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.
network
low complexity
vzug CWE-916
critical
9.8
2019-10-02 CVE-2019-12737 Use of Password Hash With Insufficient Computational Effort vulnerability in Jetbrains Ktor
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
network
low complexity
jetbrains CWE-916
5.3
2019-03-05 CVE-2019-6563 Use of Password Hash With Insufficient Computational Effort vulnerability in Moxa products
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.
network
low complexity
moxa CWE-916
critical
9.8
2019-02-17 CVE-2019-7649 Use of Password Hash With Insufficient Computational Effort vulnerability in Cmswing 1.3.7
global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing.
network
low complexity
cmswing CWE-916
7.5
2019-01-18 CVE-2019-3907 Use of Password Hash With Insufficient Computational Effort vulnerability in Identicard Premisys ID 3.1.190
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).
network
low complexity
identicard CWE-916
7.5
2019-01-15 CVE-2019-0030 Use of Password Hash With Insufficient Computational Effort vulnerability in Juniper Advanced Threat Prevention Firmware 5.0.0/5.0.1/5.0.2
Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file contents.
network
low complexity
juniper CWE-916
7.2
2018-09-05 CVE-2018-15681 Use of Password Hash With Insufficient Computational Effort vulnerability in Btiteam Xbtit 2.5.4
An issue was discovered in BTITeam XBTIT 2.5.4.
network
low complexity
btiteam CWE-916
critical
9.8
2018-09-05 CVE-2018-15680 Use of Password Hash With Insufficient Computational Effort vulnerability in Btiteam Xbtit 2.5.4
An issue was discovered in BTITeam XBTIT 2.5.4.
network
low complexity
btiteam CWE-916
critical
9.8
2018-08-01 CVE-2018-10618 Use of Password Hash With Insufficient Computational Effort vulnerability in Davolink Dvw-3200N Firmware
Davolink DVW-3200N all version prior to Version 1.00.06.
network
low complexity
davolink CWE-916
critical
9.8
2018-06-12 CVE-2017-3962 Use of Password Hash With Insufficient Computational Effort vulnerability in Mcafee Network Security Manager
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.
network
low complexity
mcafee CWE-916
critical
9.8