Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-46749

около 2 месяцев назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c5mx-3x5g-xmjx

около 2 месяцев назад

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-08433

около 2 месяцев назад

Уязвимость программного обеспечения для управления сетевой инфраструктурой SINEC INS, связанная с использованием одностороннего хеширования с предсказуемыми случайными данными, позволяющая нарушителю выполнить атаку методом перебора и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-46749

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-c5mx-3x5g-xmjx

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-08433

Уязвимость программного обеспечения для управления сетевой инфраструктурой SINEC INS, связанная с использованием одностороннего хеширования с предсказуемыми случайными данными, позволяющая нарушителю выполнить атаку методом перебора и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу