Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48vq-44vm-p326

Опубликовано: 26 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

All versions of Econolite EOS traffic control software are vulnerable to CWE-328: Use of Weak Hash, and use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.

All versions of Econolite EOS traffic control software are vulnerable to CWE-328: Use of Weak Hash, and use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.

EPSS

Процентиль: 29%
0.00105
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327
CWE-328

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.

EPSS

Процентиль: 29%
0.00105
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-327
CWE-328