Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1058

Опубликовано: 04 апр. 2006
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:busybox:busybox:1.1.1:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:avaya:aura_application_enablement_services:4.01:*:*:*:*:*:*:*
cpe:2.3:a:avaya:aura_application_enablement_services:4.1:*:*:*:*:*:*:*
cpe:2.3:a:avaya:aura_sip_enablement_services:*:*:*:*:*:*:*:*
Версия до 5.0 (исключая)
cpe:2.3:a:avaya:message_networking:*:*:*:*:*:*:*:*
cpe:2.3:a:avaya:messaging_storage_server:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 4.0 (исключая)

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 19 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

redhat
почти 20 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

CVSS3: 5.5
debian
больше 19 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which mak ...

CVSS3: 5.5
github
больше 3 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-916