CVE-2022-21800

MEDIUM

Airspan Mimosa Management Platform - Broken Cryptographic Algorithm

Title source: rule
STIX 2.1

Description

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. As a result, attackers may be able to crack the hashed passwords.

Scores

CVSS v3 6.5
EPSS 0.0008
EPSS Percentile 22.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-327 CWE-326
Status published
Products (5)
airspan/a5x_firmware < 2.5.4.1
airspan/c5c_firmware < 2.8.6.1
airspan/c5x_firmware < 2.8.6.1
airspan/c6x_firmware < 2.8.6.1
airspan/mimosa_management_platform < 1.0.3
Published Feb 18, 2022
Tracked Since Feb 18, 2026