CWE-836 · 13 kayıt
Use of Password Hash Instead of Password for Authentication
Bu sınıftaki CVE’ler
13 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2023-34132Silahlaştırılmış | Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.sonicwall · analytics · CWE-836 | Kritik9,8 | — | %7,7 | 12 Tem 2023 |
40Planlayın | CVE-2017-7927İstismar yok | A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware · CWE-836 | Yüksek7,3 | — | %36,7 | 5 May 2017 |
39İzleyin | CVE-2021-23857İstismar yok | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passworbosch · rexroth indramotion mlc l20 firmware · CWE-836 | Kritik9,8 | — | %1,2 | 4 Eki 2021 |
39İzleyin | CVE-2023-23450İstismar yok | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114sick · ftmg-esd20axx firmware · CWE-836 | Kritik9,8 | — | %0,7 | 15 May 2023 |
36İzleyin | CVE-2022-32282İstismar yok | An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.wwbn · avideo · CWE-836 | Yüksek8,8 | — | %1,8 | 22 Ağu 2022 |
36İzleyin | CVE-2026-9222İstismar yok | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authenticationshenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker · CWE-836 | Kritik9,2 | — | %0,4 | 25 Haz 2026 |
35İzleyin | CVE-2023-39546İstismar yok | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Singlenec · expresscluster x · CWE-836 | Yüksek8,8 | — | %0,6 | 17 Kas 2023 |
34İzleyin | CVE-2019-25552İstismar yok | CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Fieldcewe · photo show · CWE-836 | Yüksek8,7 | — | %0,4 | 21 Mar 2026 |
32İzleyin | CVE-2023-4299İstismar yok | Digi RealPort Protocol Use of Password Hash Instead of Password for Authenticationdigi · realport · CWE-836 | Yüksek8,1 | — | %0,7 | 31 Ağu 2023 |
30İzleyin | CVE-2025-64471İstismar yok | A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1fortinet · fortiweb · CWE-836 | Yüksek7,5 | — | %0,3 | 9 Ara 2025 |
30İzleyin | CVE-2025-48925İstismar yok | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash assmarsh · telemessage · CWE-836 | Yüksek7,5 | — | %0,3 | 28 May 2025 |
21İzleyin | CVE-2026-40103İstismar yok | Vikunja's Scoped API tokens with projects.background permission can delete project backgroundsvikunja · vikunja · CWE-836 | Orta5,4 | — | %0,3 | 10 Nis 2026 |
21İzleyin | CVE-2025-52543İstismar yok | Login to the application services using only the password hashcopeland · e3 supervisory controller firmware · CWE-836 | Orta5,3 | — | %0,3 | 2 Eyl 2025 |
- CVE-2023-3413241Planlayın
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.
KritikCVSS 9,8SilahlaştırılmışEPSS %8sonicwall · analytics12 Tem 2023
- CVE-2017-792740Planlayın
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-
YüksekCVSS 7,3İstismar yokEPSS %37dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware5 May 2017
- CVE-2021-2385739İzleyin
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor
KritikCVSS 9,8İstismar yokEPSS %1bosch · rexroth indramotion mlc l20 firmware4 Eki 2021
- CVE-2023-2345039İzleyin
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114
KritikCVSS 9,8İstismar yokEPSS %1sick · ftmg-esd20axx firmware15 May 2023
- CVE-2022-3228236İzleyin
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
YüksekCVSS 8,8İstismar yokEPSS %2wwbn · avideo22 Ağu 2022
- CVE-2026-922236İzleyin
Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
KritikCVSS 9,2İstismar yokEPSS %0shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 Haz 2026
- CVE-2023-3954635İzleyin
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Single
YüksekCVSS 8,8İstismar yokEPSS %1nec · expresscluster x17 Kas 2023
- CVE-2019-2555234İzleyin
CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
YüksekCVSS 8,7İstismar yokEPSS %0cewe · photo show21 Mar 2026
- CVE-2023-429932İzleyin
Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication
YüksekCVSS 8,1İstismar yokEPSS %1digi · realport31 Ağu 2023
- CVE-2025-6447130İzleyin
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1
YüksekCVSS 7,5İstismar yokEPSS %0fortinet · fortiweb9 Ara 2025
- CVE-2025-4892530İzleyin
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as
YüksekCVSS 7,5İstismar yokEPSS %0smarsh · telemessage28 May 2025
- CVE-2026-4010321İzleyin
Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
OrtaCVSS 5,4İstismar yokEPSS %0vikunja · vikunja10 Nis 2026
- CVE-2025-5254321İzleyin
Login to the application services using only the password hash
OrtaCVSS 5,3İstismar yokEPSS %0copeland · e3 supervisory controller firmware2 Eyl 2025