Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-11131

Опубликовано: 01 авг. 2017
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. For authentication, the user password is hashed directly with SHA-512 without a salt or another key-derivation mechanism to enable a secure secret for authentication. Moreover, only the first 32 bytes of the hash are used. This allows for easy dictionary and rainbow-table attacks if an attacker has access to the password hash.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stashcat:heinekingmedia:*:*:*:*:*:android:*:*
Версия до 1.7.5 (включая)
Конфигурация 2
cpe:2.3:a:stashcat:heinekingmedia:*:*:*:*:web:*:*:*
Версия до 0.0.80w (включая)
Конфигурация 3
cpe:2.3:a:stashcat:heinekingmedia:*:*:*:*:desktop:*:*:*
Версия до 0.0.86w (включая)

EPSS

Процентиль: 34%
0.00136
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 5.9
github
больше 3 лет назад

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. For authentication, the user password is hashed directly with SHA-512 without a salt or another key-derivation mechanism to enable a secure secret for authentication. Moreover, only the first 32 bytes of the hash are used. This allows for easy dictionary and rainbow-table attacks if an attacker has access to the password hash.

EPSS

Процентиль: 34%
0.00136
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-916