VYPR

CWE-916

Use of Password Hash With Insufficient Computational Effort

BaseIncomplete

Description

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-55

CVEs mapped to this weakness (133)

page 5 of 7
  • CVE-2024-31464MedApr 10, 2024
    risk 0.37cvss 6.8epss 0.00

    XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the password is deleted. Using that…

  • CVE-2021-38314MedSep 2, 2021
    risk 0.37cvss 5.3epss 0.29

    The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable…

  • CVE-2026-30785MedMar 5, 2026
    risk 0.36cvss 5.5epss 0.00

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config…

  • CVE-2021-33003MedAug 30, 2021
    risk 0.36cvss 5.5epss 0.00

    Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

  • CVE-2020-10538MedFeb 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.

  • CVE-2020-10040MedJul 14, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with local access to the device might be able to retrieve some passwords in clear text.

  • CVE-2018-13811MedDec 13, 2018
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exploited by an attacker…

  • CVE-2017-3962MedJun 12, 2018
    risk 0.36cvss 5.6epss 0.00

    Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.

  • CVE-2006-1058MedApr 4, 2006
    risk 0.36cvss 5.5epss 0.00

    BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

  • CVE-2026-44611MedMay 29, 2026
    risk 0.35cvss 5.4epss 0.00

    Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

  • CVE-2024-55057MedDec 17, 2024
    risk 0.35cvss 5.4epss 0.00

    Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

  • CVE-2022-23348MedMar 21, 2022
    risk 0.35cvss 5.3epss 0.03

    BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

  • CVE-2021-37551MedAug 6, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

  • CVE-2019-20575MedMar 24, 2020
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).

  • CVE-2019-12737MedOct 2, 2019
    risk 0.35cvss 5.3epss 0.01

    UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.

  • CVE-2026-9641MedJun 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm,…

  • CVE-2025-67168MedDec 17, 2025
    risk 0.34cvss 5.3epss 0.00

    RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

  • CVE-2022-40258MedJan 31, 2023
    risk 0.34cvss 5.3epss 0.00

    AMI Megarac Weak password hashes for Redfish & API

  • CVE-2018-15717MedDec 12, 2018
    risk 0.34cvss 5.3epss 0.01

    Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.

  • CVE-2026-53762MedAug 21, 2026
    risk 0.33cvss 6.2epss 0.00

    VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header key derivation through derive_key_sha256 and derive_key_sha512 in…