CWE-916

Use of Password Hash With Insufficient Computational Effort

Parent: CWE-328 - Use of Weak Hash

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

110 vulnerabilities with CWE-916
CVE-2022-0022 MEDIUM
Palo Alto Networks PAN-OS - Password Cracking
CVSS 4.1
CVE-2021-32997 HIGH
Baker Hughes Bentley Nevada - Info Disclosure
CVSS 8.2
CVE-2021-26113 MEDIUM
FortiWAN <4.5.9 - Info Disclosure
CVSS 6.2
CVE-2021-43989 HIGH
mySCADA myPRO <8.20.0 - Info Disclosure
CVSS 7.5
CVE-2021-38979 HIGH
IBM Tivoli Key Lifecycle Manager <4.1 - Info Disclosure
CVSS 7.5
CVE-2021-39182 HIGH
EnroCrypt <1.1.4 - Info Disclosure
CVSS 7.5
CVE-2021-36767 CRITICAL
Digi RealPort <4.10.490 - Info Disclosure
CVSS 9.8
CVE-2021-38400 MEDIUM
Boston Scientific Zoom Latitude Model 3120 - Info Disclosure
CVSS 6.9
CVE-2021-38314 MEDIUM
Gutenberg Template Library & Redux Framework < 4.2.11 - Information Disclosure
CVSS 5.3
CVE-2021-33003 MEDIUM
Delta Electronics DIAEnergie <1.7.5 - Info Disclosure
CVSS 5.5
CVE-2021-37551 MEDIUM
JetBrains YouTrack <2021.2.16363 - Info Disclosure
CVSS 5.3
CVE-2021-32596 MEDIUM
FortiPortal <6.04 - Info Disclosure
CVSS 6.0
CVE-2021-22774 HIGH
EVlink City/EVlink Parking/EVlink Smart Wallbox <R8 V3.4.0.1 - Info...
CVSS 7.5
CVE-2021-32519 CRITICAL
QSAN Storage Manager <3.3.2, XEVO <2.1.0, SANOS <2.1.0 - Info Discl...
CVSS 9.8
CVE-2021-22741 MEDIUM
ClearSCADA/EcoStruxure Geo SCADA Expert <2020 V83.7742.1 - Info Dis...
CVSS 6.7
CVE-2021-33563 HIGH
Koel <5.1.4 - Info Disclosure
CVSS 7.5
CVE-2021-21253 MEDIUM
OnlineVotingSystem <1.1.2 - Info Disclosure
CVSS 5.8
CVE-2020-12069 HIGH
CODESYS V3 <V3.5.16.0 - Privilege Escalation
CVSS 7.8
CVE-2020-16231 HIGH
Bachmann Electronic M-Base Controllers MSYS v1.06.14+ - Info Disclo...
CVSS 7.2
CVE-2020-25754 HIGH
Enphase Envoy R3.x-D4.x - Privilege Escalation
CVSS 7.5
CVE-2020-14516 CRITICAL
Rockwell Automation FactoryTalk Services Platform <6.11.00 - Info D...
CVSS 10.0
CVE-2020-28873 HIGH
Fluxbb - Denial of Service
CVSS 7.5
CVE-2020-10538 MEDIUM
Epikur <20.1.1 - Info Disclosure
CVSS 5.5
CVE-2020-6780 MEDIUM
Bosch FSM-2500/FSM-5000 <5.2 - Info Disclosure
CVSS 4.4
CVE-2020-14389 HIGH
Keycloak <12.0.0 - Privilege Escalation
CVSS 8.1
Details
Vulnerabilities 110