PT-2008-3085 · Zyxel · Zyxel Prestige

CVE-2008-1526

·

Publicado

2008-03-26

·

Atualizado

2024-02-14

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZyXEL Prestige routers versions 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3)
Description The issue is related to the calculation of an MD5 password hash without using a salt, making it easier for attackers to crack passwords.
Recommendations For versions 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), consider updating the firmware to a version that uses a salt when calculating password hashes as a mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1526

Produtos afetados

Zyxel Prestige