CVE-2020-1749412.11.2020, 21:15Untangle Firewall NG before 16.0 uses MD5 for passwords.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST5.3 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 37%VendorProductVersionuntangleuntangle_firewall_ng𝑥< 16.0𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-326 - Inadequate Encryption StrengthThe software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.Referenceshttps://github.com/untangle/ngfw_src/blob/1d232efe2c17a8838b59bbbeaf166dafa94676af/uvm/hier/usr/share/untangle/web/auth/index.py#L196-L200https://github.com/untangle/ngfw_src/search?q=author%3Abmastbergen+committer-date%3A2020-08-10&type=commitshttps://pastebin.com/s7UYG3vXhttps://wiki.untangle.com/index.php/16.0.0_-_16.0.1_Changeloghttps://github.com/untangle/ngfw_src/blob/1d232efe2c17a8838b59bbbeaf166dafa94676af/uvm/hier/usr/share/untangle/web/auth/index.py#L196-L200https://github.com/untangle/ngfw_src/search?q=author%3Abmastbergen+committer-date%3A2020-08-10&type=commitshttps://pastebin.com/s7UYG3vXhttps://wiki.untangle.com/index.php/16.0.0_-_16.0.1_Changelog