İçeriğe atla
Noroxi

CWE-836 · 13 kayıt

Use of Password Hash Instead of Password for Authentication

Bu sınıftaki CVE’ler

13 kayıt

  • CVE-2023-34132
    41Planlayın

    Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.

    KritikCVSS 9,8SilahlaştırılmışEPSS %8

    sonicwall · analytics12 Tem 2023

  • CVE-2017-7927
    40Planlayın

    A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-

    YüksekCVSS 7,3İstismar yokEPSS %37

    dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware5 May 2017

  • CVE-2021-23857
    39İzleyin

    Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor

    KritikCVSS 9,8İstismar yokEPSS %1

    bosch · rexroth indramotion mlc l20 firmware4 Eki 2021

  • CVE-2023-23450
    39İzleyin

    Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114

    KritikCVSS 9,8İstismar yokEPSS %1

    sick · ftmg-esd20axx firmware15 May 2023

  • CVE-2022-32282
    36İzleyin

    An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

    YüksekCVSS 8,8İstismar yokEPSS %2

    wwbn · avideo22 Ağu 2022

  • CVE-2026-9222
    36İzleyin

    Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication

    KritikCVSS 9,2İstismar yokEPSS %0

    shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 Haz 2026

  • CVE-2023-39546
    35İzleyin

    CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Single

    YüksekCVSS 8,8İstismar yokEPSS %1

    nec · expresscluster x17 Kas 2023

  • CVE-2019-25552
    34İzleyin

    CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field

    YüksekCVSS 8,7İstismar yokEPSS %0

    cewe · photo show21 Mar 2026

  • CVE-2023-4299
    32İzleyin

    Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication

    YüksekCVSS 8,1İstismar yokEPSS %1

    digi · realport31 Ağu 2023

  • CVE-2025-64471
    30İzleyin

    A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1

    YüksekCVSS 7,5İstismar yokEPSS %0

    fortinet · fortiweb9 Ara 2025

  • CVE-2025-48925
    30İzleyin

    The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as

    YüksekCVSS 7,5İstismar yokEPSS %0

    smarsh · telemessage28 May 2025

  • CVE-2026-40103
    21İzleyin

    Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds

    OrtaCVSS 5,4İstismar yokEPSS %0

    vikunja · vikunja10 Nis 2026

  • CVE-2025-52543
    21İzleyin

    Login to the application services using only the password hash

    OrtaCVSS 5,3İstismar yokEPSS %0

    copeland · e3 supervisory controller firmware2 Eyl 2025

Tüm zafiyet sınıfları