CWE-916
120 CVEs • Abstraction: Base
Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
CVEs (120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Mar 18, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user pass...Show more |
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory...Show more |
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, sinc...Show more |
1Bosch 2Fsm 2500 Firmware Fsm 5000 FirmwareJun 17, 2026 Jan 26, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the cr...Show more |
1Onlinevotingsystem Project 1Onlinevotingsystem Jun 17, 2026 Jan 21, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of secur...Show more |
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to h...Show more |
1Trendmicro 1Interscan Messaging Security Virtual Appliance Jun 17, 2026 Nov 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated. |
DomainMOD before 4.14.0 uses MD5 without a salt for password storage. |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Aug 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords. |
1Siemens 3Sicam Mmu Firmware Sicam Sgu FirmwareSicam T FirmwareJun 17, 2026 Jul 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in c...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens. |
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019). |
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP D...Show more |
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack,...Show more |
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a...Show more |
1Http Authentication Library Project 1Http Authentication Library Jun 17, 2026 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used. |
The Bitwarden server through 1.32.0 has a potentially unwanted KDF. |
2Debian Net Ldap Project2Debian Linux Net LdapNov 21, 2024 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords. |
2Debian Shibboleth2Debian Linux Service ProviderNov 21, 2024 Nov 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more |
1Vzug 1Combi Stream Mslq Firmware Jun 17, 2026 Oct 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort. |