VYPR

CWE-916

Use of Password Hash With Insufficient Computational Effort

BaseIncomplete

Description

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-55

CVEs mapped to this weakness (123)

page 6 of 7
  • CVE-2025-46413MedNov 7, 2025
    risk 0.28cvss 4.3epss 0.00

    Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password may be obtained by an attacker.

  • CVE-2022-29731MedJun 2, 2022
    risk 0.28cvss 4.3epss 0.00

    An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.

  • CVE-2026-56272MedJun 24, 2026
    risk 0.27cvss 4.1epss 0.00

    Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user…

  • CVE-2025-53884MedSep 17, 2025
    risk 0.27cvss 5.3epss 0.00

    NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed).

  • CVE-2024-29886MedMar 27, 2024
    risk 0.27cvss 5.3epss 0.00

    Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised. This vulnerability is fixed by 1.2.6.

  • CVE-2023-41646MedSep 7, 2023
    risk 0.27cvss 5.3epss 0.00

    Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/

  • CVE-2022-0022MedMar 9, 2022
    risk 0.27cvss 4.1epss 0.00

    Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal…

  • CVE-2025-27552MedMar 26, 2025
    risk 0.26cvss 4.0epss 0.00

    DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files Crypt/Eksblowfish/Bcrypt.pm. This issue affects DBIx::Class::EncodedColumn until 0.00032.

  • CVE-2025-27551MedMar 26, 2025
    risk 0.26cvss 4.0epss 0.00

    DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files lib/DBIx/Class/EncodedColumn/Digest.pm. This issue affects DBIx::Class::EncodedColumn until 0.00032.

  • CVE-2025-2349LowMar 16, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/passwd of the component Password Hash Handler. The manipulation leads to password hash with…

  • CVE-2022-31177LowAug 1, 2022
    risk 0.18cvss 2.7epss 0.01

    Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made by using partial hashed…

  • CVE-2025-7789LowJul 18, 2025
    risk 0.17cvss 3.7epss 0.00

    A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to…

  • CVE-2026-49005LowAug 7, 2026
    risk 0.16cvss 2.4epss 0.00

    The root password hash of the device can be obtained through unencrypted information in the firmware.

  • CVE-2023-4986LowSep 15, 2023
    risk 0.16cvss 2.5epss 0.00

    A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerability is an unknown functionality of the file Project.xml. The manipulation leads to password hash with insufficient computational effort. Local access is…

  • CVE-2024-21754LowJun 11, 2024
    risk 0.12cvss 1.8epss 0.03

    A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions may…

  • CVE-2024-2365LowMar 11, 2024
    risk 0.10cvss 1.6epss 0.00

    A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the component SHA-1 Handler. The manipulation leads to…

  • CVE-2026-57310MedJul 20, 2026
    risk 0.00cvss epss 0.00

    Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version…

  • CVE-2026-40522HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL…

  • CVE-2026-55069HigJun 26, 2026
    risk 0.00cvss 8.7epss 0.00

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit…

  • CVE-2021-21253MedJan 21, 2021
    risk 0.00cvss 5.8epss 0.01

    OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Without a salt, it is much…