SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-0009

Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.

MEDIUM 4.3EPSS 1.88%

Does this matter?

Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.

Description

Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.88% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
bestpractical/rt
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.