CWE-916
127 CVEs • Abstraction: Base
Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
CVEs (127)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords b...Show more |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVl...Show more |
1Qsan 3Sanos Storage ManagerXevoJun 17, 2026 Jul 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulner...Show more |
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash...Show more |
1Schneider Electric 3Clearscada Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020Jun 17, 2026 May 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior...Show more |
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier. |
1Sannce 1Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware Jun 17, 2026 Apr 2, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root pas...Show more |
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Mar 18, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user pass...Show more |
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory...Show more |
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, sinc...Show more |
1Bosch 2Fsm 2500 Firmware Fsm 5000 FirmwareJun 17, 2026 Jan 26, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the cr...Show more |
1Onlinevotingsystem Project 1Onlinevotingsystem Jun 17, 2026 Jan 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of secur...Show more |
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to h...Show more |
1Trendmicro 1Interscan Messaging Security Virtual Appliance Jun 17, 2026 Nov 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated. |
DomainMOD before 4.14.0 uses MD5 without a salt for password storage. |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Aug 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords. |
1Siemens 3Sicam Mmu Firmware Sicam Sgu FirmwareSicam T FirmwareJun 17, 2026 Jul 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in c...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens. |
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019). |
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP D...Show more |