Описание
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
7.5 High
CVSS3
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.
Уязвимость программного обеспечения для управления сетевой инфраструктурой SINEC INS, связанная с использованием одностороннего хеширования с предсказуемыми случайными данными, позволяющая нарушителю выполнить атаку методом перебора и получить несанкционированный доступ к защищаемой информации
EPSS
7.5 High
CVSS3
9.8 Critical
CVSS3