Impact
The flaw resides in the MD5Encrypt routine of Ech0, where a manipulated input may trigger the use of a weak cryptographic algorithm. The CVE states that remote exploitation is possible, though the attack complexity is high and exploitation is difficult. The impact may involve compromise of confidentiality and integrity if the weak algorithm is exploited, but the exact extent of damage is not detailed in the description and is inferred from the known weaknesses of MD5.
Affected Systems
All installations of Ech0 up to version 5.4.1 are affected. The vendor explicitly advises updating to version 5.4.2 or later to mitigate the issue. No other affected product versions are listed.
Risk and Exploitability
The vulnerability scores a CVSS of 6.3, indicating medium severity. EPSS data is not available, and the defect is not in CISA KEV. The attack vector is remote, requiring the MD5Encrypt function to be invoked with crafted input. The CVE description notes a high attack complexity and that exploitation is difficult, making successful exploitation a difficult task.
OpenCVE Enrichment