CVE-2024-25102
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
06/03/2024
Last modified:
23/09/2024
Description
This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system.<br />
<br />
Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH