Skip to content
Noroxi

CWE-836 · 13 records

Use of Password Hash Instead of Password for Authentication

CVEs in this class

13 records

  • Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.

    CriticalCVSS 9.8WeaponizedEPSS 8%

    sonicwall · analyticsJul 12, 2023

  • A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-

    HighCVSS 7.3No exploitEPSS 37%

    dahuasecurity · dh-ipc-hdbw23a0rn-zs firmwareMay 5, 2017

  • Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor

    CriticalCVSS 9.8No exploitEPSS 1%

    bosch · rexroth indramotion mlc l20 firmwareOct 4, 2021

  • Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114

    CriticalCVSS 9.8No exploitEPSS 1%

    sick · ftmg-esd20axx firmwareMay 15, 2023

  • An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

    HighCVSS 8.8No exploitEPSS 2%

    wwbn · avideoAug 22, 2022

  • CVE-2026-9222
    36Monitor

    Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication

    CriticalCVSS 9.2No exploitEPSS 0%

    shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setrackerJun 25, 2026

  • CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Single

    HighCVSS 8.8No exploitEPSS 1%

    nec · expresscluster xNov 17, 2023

  • CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field

    HighCVSS 8.7No exploitEPSS 0%

    cewe · photo showMar 21, 2026

  • CVE-2023-4299
    32Monitor

    Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication

    HighCVSS 8.1No exploitEPSS 1%

    digi · realportAug 31, 2023

  • A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1

    HighCVSS 7.5No exploitEPSS 0%

    fortinet · fortiwebDec 9, 2025

  • The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as

    HighCVSS 7.5No exploitEPSS 0%

    smarsh · telemessageMay 28, 2025

  • Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds

    MediumCVSS 5.4No exploitEPSS 0%

    vikunja · vikunjaApr 10, 2026

  • Login to the application services using only the password hash

    MediumCVSS 5.3No exploitEPSS 0%

    copeland · e3 supervisory controller firmwareSep 2, 2025

All vulnerability classes