Cogent Real-Time Systems DataHub CVE-2014-2354 Insecure Password Hashing Vulnerability
BID:67773
Info
Cogent Real-Time Systems DataHub CVE-2014-2354 Insecure Password Hashing Vulnerability
| Bugtraq ID: | 67773 |
| Class: | Design Error |
| CVE: |
CVE-2014-2354 |
| Remote: | No |
| Local: | Yes |
| Published: | May 30 2014 12:00AM |
| Updated: | Mar 19 2015 09:30AM |
| Credit: | Alain Homewood |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cogent Real-Time Systems DataHub CVE-2014-2354 Insecure Password Hashing Vulnerability
Cogent Real-Time Systems DataHub is prone to a security vulnerability due to an insecure-hashing algorithm.
Successful exploits will allow the local attackers to perform cryptanalysis to recover the encrypted usernames and passwords to access the system.
Versions prior to Cogent DataHub 7.3.5 are vulnerable.
Cogent Real-Time Systems DataHub is prone to a security vulnerability due to an insecure-hashing algorithm.
Successful exploits will allow the local attackers to perform cryptanalysis to recover the encrypted usernames and passwords to access the system.
Versions prior to Cogent DataHub 7.3.5 are vulnerable.
Exploit / POC
Cogent Real-Time Systems DataHub CVE-2014-2354 Insecure Password Hashing Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cogent Real-Time Systems DataHub CVE-2014-2354 Insecure Password Hashing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cogent Real-Time Systems DataHub CVE-2014-2354 Insecure Password Hashing Vulnerability
References:
References:
- Cogent DataHub HomePage (Cogent Real-Time Systems Inc)
- Cogent DataHub Vulnerabilities (ICS-CERT)