CWE-916— Use of Password Hash With Insufficient Computational Effort
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.— MITRE CWE catalog
142 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-916page 1 of 3
- CVE-2020-14516CRITICALCVSS 10.0EG 10.02021-03-18
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being has…
- CVE-2026-85497CRITICALCVSS 9.8EG 9.82026-09-18
CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recover …
- CVE-2026-30789CRITICALCVSS 9.8EG 9.82026-03-05
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, p…
- CVE-2024-5743CRITICALCVSS 9.8EG 9.82025-01-13
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects Eve Play: through 1.1.42.
- CVE-2023-5846CRITICALCVSS 9.8EG 9.82023-11-02
Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.
- CVE-2022-37164CRITICALCVSS 9.8EG 9.82022-09-08
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much ea…
- CVE-2022-37163CRITICALCVSS 9.8EG 9.82022-09-08
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making …
- CVE-2021-36767CRITICALCVSS 9.8EG 9.82021-10-08
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The serv…
- CVE-2021-32519CRITICALCVSS 9.8EG 9.82021-07-07
Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. The referred vulnerability has been so…
- CVE-2019-20062CRITICALCVSS 9.8EG 9.82020-02-10
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
- CVE-2019-17216CRITICALCVSS 9.8EG 9.82019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort.
- CVE-2019-6563CRITICALCVSS 9.8EG 9.82019-03-05
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.
- CVE-2018-15681CRITICALCVSS 9.8EG 9.82018-09-05
An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is i…
- CVE-2018-15680CRITICALCVSS 9.8EG 9.82018-09-05
An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force atta…
- CVE-2018-10618CRITICALCVSS 9.8EG 9.82018-08-01
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.
- CVE-2005-0408CRITICALCVSS 9.8EG 9.82005-02-14
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combine…
- CVE-2001-0967CRITICALCVSS 9.8EG 9.82001-08-31
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.
- CVE-2020-12069CRITICALCVSS 7.8EG 9.82022-12-26
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low pr…
- CVE-2017-3962CRITICALCVSS 5.6EG 9.82018-06-12
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.
- CVE-2026-45787CRITICALCVSS 9.1EG 9.12026-05-28
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for syn…
- CVE-2023-46233CRITICALCVSS 9.1EG 9.12023-10-25
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it…
- CVE-2023-46133CRITICALCVSS 9.1EG 9.12023-10-25
CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry st…
- CVE-2022-25157CRITICALCVSS 9.1EG 9.12022-04-01
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R se…
- CVE-2019-19735CRITICALCVSS 9.1EG 9.12019-12-30
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by brutef…
- CVE-2020-16231HIGHCVSS 7.2EG 8.82022-05-19
The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, an…
- CVE-2026-55069HIGHCVSS 8.7EG 8.72026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the…
- CVE-2021-23855HIGHCVSS 8.6EG 8.62021-10-04
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.
- CVE-2022-36071HIGHCVSS 8.3EG 8.32022-09-02
SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secondary authentication factor. Because TOTPs are often configu…
- CVE-2021-32997HIGHCVSS 8.2EG 8.22022-05-25
The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4…
- CVE-2022-1235HIGHCVSS 8.2EG 8.22022-04-05
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- CVE-2026-62376HIGHCVSS 8.1EG 8.12026-10-09
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the …
- CVE-2024-3183HIGHCVSS 8.1EG 8.12024-06-12
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is…
- CVE-2024-25607HIGHCVSS 8.1EG 8.12024-02-20
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported ve…
- CVE-2023-33243HIGHCVSS 8.1EG 8.12023-06-15
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext pass…
- CVE-2022-25156HIGHCVSS 8.1EG 8.12022-04-01
Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi …
- CVE-2020-14389HIGHCVSS 8.1EG 8.12020-11-17
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
- CVE-2020-14512HIGHCVSS 8.1EG 8.12020-08-25
GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.
- CVE-2018-1447HIGHCVSS 5.1EG 8.12018-04-04
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recove…
- CVE-2025-2265HIGHCVSS 7.8EG 7.82025-03-13
The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. However, the number of hash bytes encoded and stored is truncat…
- CVE-2019-20466HIGHCVSS 7.8EG 7.82021-04-02
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking th…
- CVE-2018-9233HIGHCVSS 7.8EG 7.82018-04-05
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose u…
- CVE-2025-3937HIGHCVSS 7.7EG 7.72025-05-22
Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Fram…
- CVE-2026-81704HIGHCVSS 7.5EG 7.52026-08-27
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against enc…
- CVE-2026-81689HIGHCVSS 7.5EG 7.52026-08-27
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can preco…
- CVE-2024-7701HIGHCVSS 7.5EG 7.52024-12-15
Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0.
- CVE-2024-23091HIGHCVSS 7.5EG 7.52024-07-30
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
- CVE-2024-24553HIGHCVSS 7.5EG 7.52024-06-24
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is genera…
- CVE-2022-3010HIGHCVSS 7.5EG 7.52024-01-02
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.
- CVE-2023-31412HIGHCVSS 7.5EG 7.52023-08-24
The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.
- CVE-2023-34433HIGHCVSS 7.5EG 7.52023-07-07
PiiGAB M-Bus stores passwords using a weak hash algorithm.
Map vulnerabilities like CWE-916 to your infrastructure
EchelonGraph correlates every CVE — across CWE-916 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →