CWE-916
Use of Password Hash With Insufficient Computational Effort
Description
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-55
CVEs mapped to this weakness (133)
page 5 of 7| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31464 | Med | 0.37 | 6.8 | 0.00 | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the password is deleted. Using that… | ||
| CVE-2021-38314 | Med | 0.37 | 5.3 | 0.29 | Sep 2, 2021 | The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable… | ||
| CVE-2026-30785 | Med | 0.36 | 5.5 | 0.00 | Mar 5, 2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config… | ||
| CVE-2021-33003 | Med | 0.36 | 5.5 | 0.00 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm. | ||
| CVE-2020-10538 | Med | 0.36 | 5.5 | 0.00 | Feb 5, 2021 | An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack. | ||
| CVE-2020-10040 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2020 | A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in clear text. | ||
| CVE-2018-13811 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2018 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exploited by an attacker… | ||
| CVE-2017-3962 | Med | 0.36 | 5.6 | 0.00 | Jun 12, 2018 | Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes. | ||
| CVE-2006-1058 | Med | 0.36 | 5.5 | 0.00 | Apr 4, 2006 | BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables. | ||
| CVE-2026-44611 | Med | 0.35 | 5.4 | 0.00 | May 29, 2026 | Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. | ||
| CVE-2024-55057 | Med | 0.35 | 5.4 | 0.00 | Dec 17, 2024 | Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts. | ||
| CVE-2022-23348 | Med | 0.35 | 5.3 | 0.03 | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes. | ||
| CVE-2021-37551 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | ||
| CVE-2019-20575 | Med | 0.35 | 5.4 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019). | ||
| CVE-2019-12737 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. | ||
| CVE-2026-9641 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm,… | ||
| CVE-2025-67168 | Med | 0.34 | 5.3 | 0.00 | Dec 17, 2025 | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. | ||
| CVE-2022-40258 | Med | 0.34 | 5.3 | 0.00 | Jan 31, 2023 | AMI Megarac Weak password hashes for Redfish & API | ||
| CVE-2018-15717 | Med | 0.34 | 5.3 | 0.01 | Dec 12, 2018 | Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes. | ||
| CVE-2026-53762 | Med | 0.33 | 6.2 | 0.00 | Aug 21, 2026 | VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header key derivation through derive_key_sha256 and derive_key_sha512 in… |
- risk 0.37cvss 6.8epss 0.00
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the password is deleted. Using that…
- risk 0.37cvss 5.3epss 0.29
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable…
- risk 0.36cvss 5.5epss 0.00
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config…
- risk 0.36cvss 5.5epss 0.00
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in clear text.
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exploited by an attacker…
- risk 0.36cvss 5.6epss 0.00
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.
- risk 0.36cvss 5.5epss 0.00
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
- risk 0.35cvss 5.4epss 0.00
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
- risk 0.35cvss 5.4epss 0.00
Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.
- risk 0.35cvss 5.3epss 0.03
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
- risk 0.35cvss 5.4epss 0.00
An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).
- risk 0.35cvss 5.3epss 0.01
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
- risk 0.34cvss 5.3epss 0.00
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm,…
- risk 0.34cvss 5.3epss 0.00
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
- risk 0.34cvss 5.3epss 0.00
AMI Megarac Weak password hashes for Redfish & API
- risk 0.34cvss 5.3epss 0.01
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
- risk 0.33cvss 6.2epss 0.00
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header key derivation through derive_key_sha256 and derive_key_sha512 in…