Vulnerabilities (CVE)

Filtered by CWE-759
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36440 2024-11-21 N/A 6.8 MEDIUM
An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used.
CVE-2020-25164 1 Bbraun 2 Datamodule Compactplus, Spacecom 2024-11-21 5.0 MEDIUM 6.5 MEDIUM
A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface.
CVE-2024-8453 1 Planet 4 Gs-4210-24p2s, Gs-4210-24p2s Firmware, Gs-4210-24pl4c and 1 more 2024-10-04 N/A 4.9 MEDIUM
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.