← Back
CWE-916

127 CVEs • Abstraction: Base

Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

JSON object

Loading...

CVEs (127)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortiportal
Jun 17, 2026
Aug 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords b...Show more
A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker already in possession of the password store to decrypt the passwords by means of precomputed tables.Show less
1Schneider Electric
6Evlink City Evc1s22p4 Firmware
Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 more
Jun 17, 2026
Jul 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVl...Show more
A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could lead an attacker to get knowledge of charging station user account credentials using dictionary attacks techniques.Show less
1Qsan
3Sanos
Storage ManagerXevo
Jun 17, 2026
Jul 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulner...Show more
Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.2, QSAN XEVO v2.1.0, and QSAN SANOS v2.1.0.Show less
1Enphase
1Envoy Firmware
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash...Show more
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash of the username and serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. Attempts to change the user password via passwd or other tools have no effect.Show less
1Schneider Electric
3Clearscada
Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020
Jun 17, 2026
May 26, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior...Show more
Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that “.sde” configuration export files do not contain user account password hashes.Show less
1Koel
1Koel
Jun 17, 2026
May 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.
1Sannce
1Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root pas...Show more
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking this hash and cracking it, the attacker can obtain root rights on the device.Show less
1Rockwellautomation
1Factorytalk Services Platform
Jun 17, 2026
Mar 18, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user pass...Show more
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.Show less
1Fluxbb
1Fluxbb
Jul 9, 2026
Mar 17, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory...Show more
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on the server.Show less
1Epikur
1Epikur
Jun 17, 2026
Feb 5, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, sinc...Show more
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.Show less
1Bosch
2Fsm 2500 Firmware
Fsm 5000 Firmware
Jun 17, 2026
Jan 26, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the cr...Show more
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.Show less
1Onlinevotingsystem Project
1Onlinevotingsystem
Jun 17, 2026
Jan 21, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of secur...Show more
OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Without a salt, it is much easier for attackers to pre-compute the hash value using dictionary attack techniques such as rainbow tables to crack passwords. This problem is fixed and published in version 1.1.2. A long randomly generated salt is added to the password hash function to better protect passwords stored in the voting system.Show less
1Redhat
1Keycloak
Jun 17, 2026
Nov 17, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to h...Show more
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.Show less
1Trendmicro
1Interscan Messaging Security Virtual Appliance
Jun 17, 2026
Nov 9, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
1Domainmod
1Domainmod
Jun 17, 2026
Oct 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DomainMOD before 4.14.0 uses MD5 without a salt for password storage.
1Secomea
1Gatemanager 8250 Firmware
Jun 17, 2026
Aug 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.
1Siemens
3Sicam Mmu Firmware
Sicam Sgu FirmwareSicam T Firmware
Jun 17, 2026
Jul 14, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in c...Show more
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in clear text.Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
5.4 MEDIUM· v3
4.8 MEDIUM· v2
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).
1Phoner
1Phonerlite
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP D...Show more
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.Show less