PT-2019-12059 · Computrols · Cbas

Published

2019-05-23

·

Updated

2020-08-24

·

CVE-2019-10855

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Computrols CBAS version 18.0.0
Description The issue concerns the mishandling of password hashes. Specifically, it uses the MD5 hashing algorithm with a 'pw' prefix. For example, if the password is 'admin', it calculates the MD5 hash of 'pwadmin' and stores this hash in a MySQL database.
Recommendations For version 18.0.0, consider updating the password hashing mechanism to a more secure algorithm to mitigate the risk of exploitation. As a temporary workaround, restrict access to the password storage and retrieval functions to minimize the risk of unauthorized access.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10855

Affected Products

Cbas