Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cgj-crgg-xwgf

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.

EPSS

Процентиль: 78%
0.01946
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.

CVSS3: 9.8
fstec
больше 9 лет назад

Уязвимость FTP-сервера микропрограммного обеспечения программируемых логических контроллеров Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340 и BMXNOR0200, позволяющая нарушителю подобрать пароли

EPSS

Процентиль: 78%
0.01946
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-326