Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-26j2-2wp8-h95h

Опубликовано: 26 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort.

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort.

EPSS

Процентиль: 12%
0.00041
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 7.8
nvd
почти 3 года назад

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

EPSS

Процентиль: 12%
0.00041
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-916