CWE-916
120 CVEs • Abstraction: Base
Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
CVEs (120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 4Desigo Dxr2 Firmware Desigo Pxc3 FirmwareDesigo Pxc4 Firmware+1 moreJun 17, 2026 May 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142....Show more |
A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in possession of the password file to potentially guess passwords therein sto...Show more |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Apr 5, 2022 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes. |
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allo...Show more |
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes. |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the inp...Show more |
EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is consider...Show more |
1Digi 196350 Sr Firmware Cm FirmwareConnect Es Firmware+16 moreJun 17, 2026 Oct 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to t...Show more |
1Bostonscientific 1Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware Jun 17, 2026 Oct 4, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the syst...Show more |
1Redux 1Gutenberg Template Library & Redux Framework Jun 17, 2026 Sep 2, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were...Show more |
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm. |
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. |
A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords b...Show more |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVl...Show more |
1Qsan 3Sanos Storage ManagerXevoJun 17, 2026 Jul 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulner...Show more |
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash...Show more |
1Schneider Electric 3Clearscada Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020Jun 17, 2026 May 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior...Show more |
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier. |
1Sannce 1Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware Jun 17, 2026 Apr 2, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root pas...Show more |