PT-2024-10770 · Siime Eye · Siime Eye
Edwin Gozeling
+2
·
Published
2024-11-07
·
Updated
2025-04-24
·
CVE-2020-11916
CVSS v3.1
6.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Siime Eye version 14.1.00000001.3.330.0.0.3.14
Description
An issue was discovered in Siime Eye where the password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.
Recommendations
For Siime Eye version 14.1.00000001.3.330.0.0.3.14, update to the latest firmware to mitigate the risk of exploitation. As a temporary workaround, consider restricting network access to the device until a patch is available.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siime Eye