Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104940 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-212-01 | us government resource third party advisory mitigation |
https://www.exploit-db.com/exploits/45076/ | exploit vdb entry third party advisory |