Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-05-23T18:43:28

Updated: 2024-08-04T22:32:02.105Z

Reserved: 2019-04-04T00:00:00

Link: CVE-2019-10855

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-05-23T19:29:01.027

Modified: 2020-08-24T17:37:01.140

Link: CVE-2019-10855

cve-icon Redhat

No data.