PT-2024-10770 · Siime Eye · Siime Eye

Edwin Gozeling

+2

·

Published

2024-11-07

·

Updated

2025-04-24

·

CVE-2020-11916

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Siime Eye version 14.1.00000001.3.330.0.0.3.14
Description An issue was discovered in Siime Eye where the password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.
Recommendations For Siime Eye version 14.1.00000001.3.330.0.0.3.14, update to the latest firmware to mitigate the risk of exploitation. As a temporary workaround, consider restricting network access to the device until a patch is available.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2020-11916

Affected Products

Siime Eye