Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x56c-3wf3-rm6r

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.

Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.

EPSS

Процентиль: 57%
0.00355
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 9.8
nvd
больше 24 лет назад

Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.

EPSS

Процентиль: 57%
0.00355
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-916