PT-2021-9097 · Versa · Vos+2

Published

2021-05-26

·

Updated

2021-06-07

·

CVE-2019-25030

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Versa Director, Versa Analytics, and VOS (affected versions not specified)
Description The issue concerns the storage of passwords without using an adaptive cryptographic hash function or key derivation function, making them susceptible to password cracking. The use of popular hashing algorithms like MD5 and SHA-1 alone is insufficient to prevent attacks. Attackers can generate precomputed hashes, known as "rainbow tables," for all possible password character combinations relatively quickly. The use of adaptive hashing algorithms, such as scrypt, bcrypt, or Key-Derivation Functions like PBKDF2, would make generating such rainbow tables computationally infeasible.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25030

Affected Products

Vos
Versa Analytics
Versa Director