Security Advisory

CVE-2021-3833

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-10-07 15:10:07
Last updated 2024-09-16 23:46:25
Assigner INCIBE
CVSS score 9.8
State PUBLISHED

Description

Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.