CVE-2019-17216

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
06/10/2019
Last modified:
24/08/2020

Description

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:vzug:combi-stream_mslq_firmware:*:*:*:*:*:*:*:* ethernet_r07 (excluding)
cpe:2.3:h:vzug:combi-stream_mslq:-:*:*:*:*:*:*:*
cpe:2.3:o:vzug:combi-stream_mslq_firmware:*:*:*:*:*:*:*:* wlan_r05 (excluding)
cpe:2.3:h:vzug:combi-stream_mslq:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools