CVE-2020-17494
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
12/11/2020
Last modified:
21/07/2021
Description
Untangle Firewall NG before 16.0 uses MD5 for passwords.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:untangle:untangle_firewall_ng:*:*:*:*:*:*:*:* | 16.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/untangle/ngfw_src/blob/1d232efe2c17a8838b59bbbeaf166dafa94676af/uvm/hier/usr/share/untangle/web/auth/index.py#L196-L200
- https://github.com/untangle/ngfw_src/search?q=author%3Abmastbergen%20committer-date%3A2020-08-10&type=commits
- https://pastebin.com/s7UYG3vX
- https://wiki.untangle.com/index.php/16.0.0_-_16.0.1_Changelog



