CWE-916
Use of Password Hash With Insufficient Computational Effort
Parent: CWE-328 - Use of Weak Hash
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
115 vulnerabilities with CWE-916
CVE-2022-36071
HIGH
SFTPGo 2.2.0-2.3.3 - Two-Factor Authentication Bypass via Recovery Code Generation
CVSS 8.3
CVE-2022-29731
MEDIUM
ICT Protege GX/WX <2.08 - Info Disclosure
CVSS 4.3
CVE-2022-24041
MEDIUM
Desigo DXR2, PXC3, PXC4, PXC5 < V01.21.142.5-22, V02.20.142.10-1088...
CVSS 6.5
CVE-2022-1235
HIGH
GitHub livehelperchat/livehelperchat <3.96 - Info Disclosure
CVSS 8.2
CVE-2022-23348
MEDIUM
BigAnt Server <5.6.06 - Info Disclosure
CVSS 5.3
CVE-2022-0022
MEDIUM
Palo Alto Networks PAN-OS - Password Cracking
CVSS 4.1
CVE-2021-32997
HIGH
Baker Hughes Bentley Nevada - Info Disclosure
CVSS 8.2
CVE-2021-26113
MEDIUM
FortiWAN < 4.5.9 - Use of Password Hash With Insufficient Computational Effort
CVSS 6.2
CVE-2021-43989
HIGH
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 7.5
CVE-2021-38979
HIGH
IBM Tivoli Key Lifecycle Manager <4.1 - Info Disclosure
CVSS 7.5
CVE-2021-39182
HIGH
EnroCrypt < 1.1.4 - Use of Broken MD5 Hashing Algorithm
CVSS 7.5
CVE-2021-36767
CRITICAL
Digi RealPort <4.10.490 - Info Disclosure
CVSS 9.8
CVE-2021-38400
MEDIUM
Boston Scientific Zoom Latitude Model 3120 - Info Disclosure
CVSS 6.9
CVE-2021-38314
MEDIUM
Gutenberg Template Library & Redux Framework <= 4.2.11 - Sensitive Information Exposure
CVSS 5.3
CVE-2021-33003
MEDIUM
Delta Electronics DIAEnergie <1.7.5 - Info Disclosure
CVSS 5.5
CVE-2021-37551
MEDIUM
JetBrains YouTrack <2021.2.16363 - Info Disclosure
CVSS 5.3
CVE-2021-32596
MEDIUM
FortiPortal <6.04 - Info Disclosure
CVSS 6.0
CVE-2021-22774
HIGH
EVlink City/EVlink Parking/EVlink Smart Wallbox <R8 V3.4.0.1 - Info...
CVSS 7.5
CVE-2021-32519
CRITICAL
QSAN Storage Manager <3.3.2, XEVO <2.1.0, SANOS <2.1.0 - Info Discl...
CVSS 9.8
CVE-2021-22741
MEDIUM
ClearSCADA/EcoStruxure Geo SCADA Expert <2020 V83.7742.1 - Info Dis...
CVSS 6.7
CVE-2021-33563
HIGH
Koel < 5.1.4 - Insufficient Password Hash Computational Effort
CVSS 7.5
CVE-2021-21253
MEDIUM
OnlineVotingSystem <1.1.2 - Info Disclosure
CVSS 5.8
CVE-2020-12069
HIGH
CODESYS V3 <V3.5.16.0 - Privilege Escalation
CVSS 7.8
CVE-2020-16231
HIGH
Bachmann Electronic M-Base Controllers MSYS v1.06.14+ - Info Disclo...
CVSS 7.2
CVE-2020-25754
HIGH
Enphase Envoy R3.x-D4.x - Privilege Escalation
CVSS 7.5
Details
Vulnerabilities
115