PT-2022-23852 · Inoda · Inoda Ontrack
J-Gainsec
·
Published
2022-09-08
·
Updated
2023-08-08
·
CVE-2022-37164
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Inoda OnTrack version 3.4
Description
The issue is related to a weak password policy, allowing potential unauthorized access via brute-force attacks. User passwords are hashed without a salt or pepper, making it easier for tools like hashcat to crack the hashes.
Recommendations
For Inoda OnTrack version 3.4, consider implementing a stronger password policy and hashing passwords with a salt or pepper to prevent easy cracking by tools like hashcat. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Inoda Ontrack