VulnerabilityModified
CVE-2020-11916
Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.
MEDIUM 6.3EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327
- Affected
- svakom/svakom siime eye firmware
- Source
- cve@mitre.org
References
- https://seclists.org/fulldisclosure/2024/Jul/14Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/14
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.