CVE-2013-6445

Red Hat Enterprise MRG 2.5 - Weak Password Hashing via DES-based crypt Function

Title source: llm
STIX 2.1

Description

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030158
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0441.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0440.html

Scores

EPSS 0.0115
EPSS Percentile 63.5%

Details

CWE
CWE-310
Status published
Products (1)
redhat/enterprise_mrg 2.5
Published Apr 30, 2014
Tracked Since Feb 18, 2026