The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.
Workaround:
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Link | Tags |
---|---|
https://sick.com/psirt | vendor advisory issue tracking |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf | vendor advisory |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json | vendor advisory |