CVE-2021-33003
30.08.2021, 18:15
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.Enginsight
Vendor | Product | Version |
---|---|---|
deltaww | diaenergie | 𝑥 ≤ 1.7.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-916 - Use of Password Hash With Insufficient Computational EffortThe software generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
- CWE-327 - Use of a Broken or Risky Cryptographic AlgorithmThe use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.