An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code.
This issue affects Eve Play: through 1.1.42.
This issue affects Eve Play: through 1.1.42.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47157 | An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects Eve Play: through 1.1.42. |
Fixes
Solution
The issue is resolved in the version to: 1.1.43 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.evehome.com/en-us/security-content |
|
History
Mon, 13 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Jan 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects Eve Play: through 1.1.42. | |
| Title | Command Injection Vulnerability | |
| Weaknesses | CWE-916 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2025-01-13T18:25:58.273Z
Reserved: 2024-06-07T12:34:00.963Z
Link: CVE-2024-5743
Updated: 2025-01-13T18:25:50.814Z
Status : Received
Published: 2025-01-13T18:15:19.517
Modified: 2025-01-13T18:15:19.517
Link: CVE-2024-5743
No data.
OpenCVE Enrichment
No data.
EUVD