Description
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file.

This issue was fixed in version v3.17-2000.
Published: 2026-07-10
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

R‑SOFT DMS uses a non‑salted nested MD5 hash to store superadmin passwords, a weakness identified as CWE‑328. This allows anyone who learns the hash to reverse‑engineer the credential, thereby gaining privileged access. Because the password can only be changed by editing a protected configuration file, an attacker who obtains the hash can maintain long‑term control over the system.

Affected Systems

The vulnerability impacts R‑SOFT SERWIS:DMS; any installation running a version prior to the fixed release v3.17‑2000 is vulnerable. Exact version numbers are not listed in the input, but the issue was patched in v3.17‑2000.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests low current exploitation probability. Because no exploits are reported and the vulnerability is not listed in the CISA KEV catalog, it is unlikely to be widely abused at present. The attack vector is inferred to be obtainable hash extraction, possibly via local or remote means if the attacker can read the configuration file.

Generated by OpenCVE AI on July 29, 2026 at 11:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade R‑SOFT DMS to version v3.17‑2000 or later
  • After upgrading, configure a strong, unique superadmin password and optionally enable additional authentication controls
  • Ensure the configuration file’s permissions restrict access to privileged users only and consider encrypting the file
  • Implement a salted hash mechanism for superadmin passwords to mitigate the CWE‑328 weakness

Generated by OpenCVE AI on July 29, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared R-soft Serwis
R-soft Serwis dms
Vendors & Products R-soft Serwis
R-soft Serwis dms

Fri, 10 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.
Title Weak password hashing in R-SOFT DMS
Weaknesses CWE-328
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

R-soft Serwis Dms
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-10T10:19:29.636Z

Reserved: 2026-04-22T11:32:15.204Z

Link: CVE-2026-41879

cve-icon Vulnrichment

Updated: 2026-07-10T10:19:19.999Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:15:04Z

Weaknesses