Password Hashing Vulnerability in Computrols CBAS by Computrols
CVE-2019-10855
7.5HIGH
What is CVE-2019-10855?
The Computrols CBAS 18.0.0 product has a security weakness in its password hashing mechanism. Instead of employing a strong hashing algorithm, it uses MD5 with a simple prefix, leading to potential exposure of user passwords stored in its MySQL database. This flawed approach can make it easier for attackers to reverse-engineer the plaintext passwords, jeopardizing user account security and access controls within the system.
