CVE-2019-10855 Information
Feb 14, 2021
cve
Description
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix e.g. if the password is admin it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://applied-risk.com/index.php/download_file/view/196/165 https://applied-risk.com/labs/advisories
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: