CVE-2022-21800
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. As a result, attackers may be able to crack the hashed passwords.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.6.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan C6x | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.6.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan C5x | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.6.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan C5c | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.4.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan A5x | All versions |
Related CWEs
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.