CVE-2019-5723
CRITICALPortier - Insufficiently Protected Credentials
Title source: ruleDescription
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the used Vigenere algorithm is badly outdated. Moreover, the encryption key is static and too short. Due to this, the passwords stored by the application can be easily decrypted.
References (3)
Scores
CVSS v3
9.8
EPSS
0.0014
EPSS Percentile
34.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
CWE-327
Status
published
Affected Products (2)
portier/portier
portier/portier
Timeline
Published
Mar 21, 2019
Tracked Since
Feb 18, 2026