Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2018-44 | third party advisory |