CVEbaza.plSłownik CWECWE-836
Common Weakness Enumeration

CWE-836

Use of Password Hash Instead of Password for Authentication

Kategoria: BaseCVE: 16
Opis

Produkt przechowuje skróty haseł w magazynie danych, otrzymuje skrót hasła od klienta i porównuje dostarczony skrót ze skrótem pobranym z magazynu danych. Ta praktyka stanowi zagrożenie bezpieczeństwa, ponieważ skrót hasła może być użyty jako uwierzytelniające dane dostępowe bez znajomości oryginalnego hasła.

Description (EN)

The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

Podatności CVE z CWE-836 (16)
10.0
CVSS
CRITICAL
CVE-2021-23857

Podatność w urządzeniach Bosch Rexroth IndraMotion MLC pozwala atakującemu zalogować się do systemu przy użyciu hashu hasła zamiast samego hasła. W połączeniu z CVE-2021-23858 umożliwia to pełne przejęcie dostępu do systemu bez znajomości oryginalnego hasła.

pub. 2021-10-04
9.8
CVSS
CRITICAL
CVE-2023-34132

Podatność w SonicWall GMS i Analytics polega na użyciu skrótu hasła (hash) zamiast samego hasła podczas uwierzytelniania, co umożliwia przeprowadzenie ataku Pass-the-Hash. Jest to krytyczna luka, ponieważ atakujący bez znajomości właściwego hasła może przejąć kontrolę nad systemem.

pub. 2023-07-13
9.2
CVSS
CRITICAL
CVE-2026-9222

Aplikacja mobilna Setracker2 na Android (com.tgelec.setracker) w wersjach 3.1.5 i wcześniejszych przesyła do usług backendowych wyłącznie hash hasła zamiast pełnego procesu uwierzytelnienia. Atakujący, który wejdzie w posiadanie hasha, może uzyskać pełny dostęp do konta bez znajomości hasła jawnego.

pub. 2026-06-26
9.0
CVSS
CRITICAL
CVE-2023-4299

Protokół Digi RealPort jest podatny na atak typu replay, który umożliwia napastnikowi ominięcie mechanizmu uwierzytelnienia. Skuteczny atak daje nieautoryzowany dostęp do urządzeń podłączonych przez serwery portów szeregowych.

pub. 2023-08-31
8.8
CVSS
HIGH
CVE-2023-39546

CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.

pub. 2023-11-17
8.8
CVSS
HIGH
CVE-2023-23614

Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes it possible for an attacker to "pass the hash" to login or reuse a theoretically expired "remember me" cookie. It also exposes the hash over the network and stores it unnecessarily in the browser. The cookie itself is set to expire after 7 days but its value will remain valid as long as the admin password doesn't change. If a cookie is leaked or compromised it could be used forever as long as the admin password is not changed. An attacker that obtained the password hash via an other attack vector (for example a path traversal vulnerability) could use it to login as the admin by setting the hash as the cookie value without the need to crack it to obtain the admin password (pass the hash). The hash is exposed over the network and in the browser where the cookie is transmitted and stored. This issue is patched in version 5.18.3.

pub. 2023-01-26
8.8
CVSS
HIGH
CVE-2022-32282

An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.

pub. 2022-08-22
8.7
CVSS
HIGH
CVE-2019-25552

CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Attackers can paste a large string of repeated characters into the password input during the upload process to trigger an application crash.

pub. 2026-03-21
8.6
CVSS
HIGH
CVE-2025-62618

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.

pub. 2025-10-31
7.3
CVSS
HIGH
CVE-2017-7927

A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password.

pub. 2017-05-06
6.5
CVSS
MEDIUM
CVE-2026-44736

OpenProject to otwarte, internetowe oprogramowanie do zarządzania projektami. Przed wersją 17.4.0 endpoint GET /api/v3/relations pozwalał każdemu uwierzytelnionemu użytkownikowi pobierać relacje oraz temat (tytuł) pakietów pracy, do których nie miał uprawnień dostępu, poprzez podanie arbitralnego ID pakietu pracy w filtrach involved, fromId lub toId. Luka ta omijała scope Relation.visible ze względu na wadliwą optymalizację wydajności w RelationQuery. Podatność została naprawiona w wersji 17.4.0.

pub. 2026-06-26
6.2
CVSS
MEDIUM
CVE-2023-23450

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.

pub. 2023-05-15
5.3
CVSS
MEDIUM
CVE-2025-52543

E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.

pub. 2025-09-02
4.9
CVSS
MEDIUM
CVE-2025-64471

Podatność polegająca na użyciu hasza hasła zamiast samego hasła do uwierzytelnienia [CWE-836] w Fortinet FortiWeb 8.0.0 do 8.0.1, FortiWeb 7.6.0 do 7.6.5, FortiWeb 7.4.0 do 7.4.10, FortiWeb 7.2.0 do 7.2.11 i FortiWeb 7.0.0 do 7.0.11 może pozwolić niezauwierzytelnionemu atakującemu na uwierzytelnienie się przy użyciu hasza zamiast hasła poprzez spreparowane żądania HTTP/HTTPS.

pub. 2025-12-09
4.3
CVSS
MEDIUM
CVE-2026-40103

Vikunja to open-source'owa platforma do zarządzania zadaniami obsługiwana na własnych serwerach. Przed wersją 2.3.0 egzekwowanie scoped API token dla tras niestandardowych teł projektów w Vikunji było podatne na method confusion. Token ze scope'em tylko projects.background mógł pomyślnie usunąć tło projektu, podczas gdy token ze scope'em tylko projects.background_delete został odrzucony. Jest to bypass autoryzacji scoped token. Podatność została naprawiona w wersji 2.3.0.

pub. 2026-04-10
4.3
CVSS
MEDIUM
CVE-2025-48925

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.

pub. 2025-05-28
Informacje
ID: CWE-836
Typ: Base
Podatności: 16
MITRE CWE ↗
← Słownik CWE