Перейти к содержимому
Noroxi

CWE-836 · 13 записей

Use of Password Hash Instead of Password for Authentication

CVE этого класса

13 записей

  • CVE-2023-34132
    41В плане

    Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 8 %

    sonicwall · analytics12 июл. 2023 г.

  • CVE-2017-7927
    40В плане

    A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-

    ВысокаяCVSS 7,3Эксплойта нетEPSS 37 %

    dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware5 мая 2017 г.

  • CVE-2021-23857
    39Наблюдать

    Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    bosch · rexroth indramotion mlc l20 firmware4 окт. 2021 г.

  • CVE-2023-23450
    39Наблюдать

    Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sick · ftmg-esd20axx firmware15 мая 2023 г.

  • CVE-2022-32282
    36Наблюдать

    An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    wwbn · avideo22 авг. 2022 г.

  • CVE-2026-9222
    36Наблюдать

    Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 июн. 2026 г.

  • CVE-2023-39546
    35Наблюдать

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Single

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    nec · expresscluster x17 нояб. 2023 г.

  • CVE-2019-25552
    34Наблюдать

    CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    cewe · photo show21 мар. 2026 г.

  • CVE-2023-4299
    32Наблюдать

    Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    digi · realport31 авг. 2023 г.

  • CVE-2025-64471
    30Наблюдать

    A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    fortinet · fortiweb9 дек. 2025 г.

  • CVE-2025-48925
    30Наблюдать

    The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    smarsh · telemessage28 мая 2025 г.

  • CVE-2026-40103
    21Наблюдать

    Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    vikunja · vikunja10 апр. 2026 г.

  • CVE-2025-52543
    21Наблюдать

    Login to the application services using only the password hash

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    copeland · e3 supervisory controller firmware2 сент. 2025 г.

Все классы уязвимостей