CVE-2024-24553
HIGHDescription
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.
Is your site exposed to CVE-2024-24553?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| bludit | bludit |
References
Frequently Asked Questions
What is CVE-2024-24553? +
How severe is CVE-2024-24553? +
What products are affected by CVE-2024-24553? +
How do I check if I'm vulnerable to CVE-2024-24553? +
Related Vulnerabilities
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password …
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in …
The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and …
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an …
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute …
CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to …