SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11916

Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.

MEDIUM 6.3EPSS 0.49%

Does this matter?

Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking attack is greatly increased.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
0.49% probability · 41th percentile
CISA KEV
Not listed
Weakness
CWE-327
Affected
svakom/svakom siime eye firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.