CVE-2024-8453
CVE-2024-8453
Título es
CVE-2024-8453
Lun, 30/09/2024 – 08:15
Tipo
CWE-328
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-8453
Descripción en
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.
30/09/2024
30/09/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.90
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
Enviar en el boletín
Off