← Back
CWE-916

120 CVEs • Abstraction: Base

Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

JSON object

Loading...

CVEs (120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockwellautomation
1Factorytalk Services Platform
Jun 17, 2026
Mar 18, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user pass...Show more
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.Show less
1Fluxbb
1Fluxbb
Jul 9, 2026
Mar 17, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory...Show more
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on the server.Show less
1Epikur
1Epikur
Jun 17, 2026
Feb 5, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, sinc...Show more
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.Show less
1Bosch
2Fsm 2500 Firmware
Fsm 5000 Firmware
Jun 17, 2026
Jan 26, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the cr...Show more
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.Show less
1Onlinevotingsystem Project
1Onlinevotingsystem
Jun 17, 2026
Jan 21, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of secur...Show more
OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Without a salt, it is much easier for attackers to pre-compute the hash value using dictionary attack techniques such as rainbow tables to crack passwords. This problem is fixed and published in version 1.1.2. A long randomly generated salt is added to the password hash function to better protect passwords stored in the voting system.Show less
1Redhat
1Keycloak
Jun 17, 2026
Nov 17, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to h...Show more
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.Show less
1Trendmicro
1Interscan Messaging Security Virtual Appliance
Jun 17, 2026
Nov 9, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
1Domainmod
1Domainmod
Jun 17, 2026
Oct 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DomainMOD before 4.14.0 uses MD5 without a salt for password storage.
1Secomea
1Gatemanager 8250 Firmware
Jun 17, 2026
Aug 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.
1Siemens
3Sicam Mmu Firmware
Sicam Sgu FirmwareSicam T Firmware
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in c...Show more
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in clear text.Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
5.4 MEDIUM· v3
4.8 MEDIUM· v2
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).
1Phoner
1Phonerlite
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP D...Show more
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.Show less
1Google
1Gizmo5
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack,...Show more
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.Show less
1Mfscripts
1Yetishare
Jun 17, 2026
Dec 30, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a...Show more
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.Show less
1Http Authentication Library Project
1Http Authentication Library
Jun 17, 2026
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.
1Bitwarden
1Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
2Debian
Net Ldap Project
2Debian Linux
Net Ldap
Nov 21, 2024
Nov 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
2Debian
Shibboleth
2Debian Linux
Service Provider
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.Show less
1Vzug
1Combi Stream Mslq Firmware
Jun 17, 2026
Oct 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort.