Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5mx-3x5g-xmjx

Опубликовано: 09 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5
CVSS3: 7.5

Описание

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

EPSS

Процентиль: 2%
0.00121
Низкий

5 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-760

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость программного обеспечения для управления сетевой инфраструктурой SINEC INS, связанная с использованием одностороннего хеширования с предсказуемыми случайными данными, позволяющая нарушителю выполнить атаку методом перебора и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00121
Низкий

5 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-760