Insecure Password Hashing in Computrols CBAS 18.0.0

Insecure Password Hashing in Computrols CBAS 18.0.0

CVE-2019-10855 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.