PT-2019-12059 · Computrols · Cbas
Published
2019-05-23
·
Updated
2020-08-24
·
CVE-2019-10855
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Computrols CBAS version 18.0.0
Description
The issue concerns the mishandling of password hashes. Specifically, it uses the MD5 hashing algorithm with a 'pw' prefix. For example, if the password is 'admin', it calculates the MD5 hash of 'pwadmin' and stores this hash in a MySQL database.
Recommendations
For version 18.0.0, consider updating the password hashing mechanism to a more secure algorithm to mitigate the risk of exploitation. As a temporary workaround, restrict access to the password storage and retrieval functions to minimize the risk of unauthorized access.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cbas