CWE-836 · 13 записей
Use of Password Hash Instead of Password for Authentication
CVE этого класса
13 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2023-34132Готовый эксплойт | Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.sonicwall · analytics · CWE-836 | Критическая9,8 | — | 7,7 % | 12 июл. 2023 г. |
40В плане | CVE-2017-7927Эксплойта нет | A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware · CWE-836 | Высокая7,3 | — | 36,7 % | 5 мая 2017 г. |
39Наблюдать | CVE-2021-23857Эксплойта нет | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passworbosch · rexroth indramotion mlc l20 firmware · CWE-836 | Критическая9,8 | — | 1,2 % | 4 окт. 2021 г. |
39Наблюдать | CVE-2023-23450Эксплойта нет | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114sick · ftmg-esd20axx firmware · CWE-836 | Критическая9,8 | — | 0,7 % | 15 мая 2023 г. |
36Наблюдать | CVE-2022-32282Эксплойта нет | An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.wwbn · avideo · CWE-836 | Высокая8,8 | — | 1,8 % | 22 авг. 2022 г. |
36Наблюдать | CVE-2026-9222Эксплойта нет | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authenticationshenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker · CWE-836 | Критическая9,2 | — | 0,4 % | 25 июн. 2026 г. |
35Наблюдать | CVE-2023-39546Эксплойта нет | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Singlenec · expresscluster x · CWE-836 | Высокая8,8 | — | 0,6 % | 17 нояб. 2023 г. |
34Наблюдать | CVE-2019-25552Эксплойта нет | CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Fieldcewe · photo show · CWE-836 | Высокая8,7 | — | 0,4 % | 21 мар. 2026 г. |
32Наблюдать | CVE-2023-4299Эксплойта нет | Digi RealPort Protocol Use of Password Hash Instead of Password for Authenticationdigi · realport · CWE-836 | Высокая8,1 | — | 0,7 % | 31 авг. 2023 г. |
30Наблюдать | CVE-2025-64471Эксплойта нет | A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1fortinet · fortiweb · CWE-836 | Высокая7,5 | — | 0,3 % | 9 дек. 2025 г. |
30Наблюдать | CVE-2025-48925Эксплойта нет | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash assmarsh · telemessage · CWE-836 | Высокая7,5 | — | 0,3 % | 28 мая 2025 г. |
21Наблюдать | CVE-2026-40103Эксплойта нет | Vikunja's Scoped API tokens with projects.background permission can delete project backgroundsvikunja · vikunja · CWE-836 | Средняя5,4 | — | 0,3 % | 10 апр. 2026 г. |
21Наблюдать | CVE-2025-52543Эксплойта нет | Login to the application services using only the password hashcopeland · e3 supervisory controller firmware · CWE-836 | Средняя5,3 | — | 0,3 % | 2 сент. 2025 г. |
- CVE-2023-3413241В плане
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.
КритическаяCVSS 9,8Готовый эксплойтEPSS 8 %sonicwall · analytics12 июл. 2023 г.
- CVE-2017-792740В плане
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-
ВысокаяCVSS 7,3Эксплойта нетEPSS 37 %dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware5 мая 2017 г.
- CVE-2021-2385739Наблюдать
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · rexroth indramotion mlc l20 firmware4 окт. 2021 г.
- CVE-2023-2345039Наблюдать
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · ftmg-esd20axx firmware15 мая 2023 г.
- CVE-2022-3228236Наблюдать
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %wwbn · avideo22 авг. 2022 г.
- CVE-2026-922236Наблюдать
Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 июн. 2026 г.
- CVE-2023-3954635Наблюдать
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Single
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nec · expresscluster x17 нояб. 2023 г.
- CVE-2019-2555234Наблюдать
CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %cewe · photo show21 мар. 2026 г.
- CVE-2023-429932Наблюдать
Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %digi · realport31 авг. 2023 г.
- CVE-2025-6447130Наблюдать
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fortinet · fortiweb9 дек. 2025 г.
- CVE-2025-4892530Наблюдать
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %smarsh · telemessage28 мая 2025 г.
- CVE-2026-4010321Наблюдать
Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
СредняяCVSS 5,4Эксплойта нетEPSS 0 %vikunja · vikunja10 апр. 2026 г.
- CVE-2025-5254321Наблюдать
Login to the application services using only the password hash
СредняяCVSS 5,3Эксплойта нетEPSS 0 %copeland · e3 supervisory controller firmware2 сент. 2025 г.