ZeroHour

CVE-2023-31412

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
Description

The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.

Vendors
sick
Products
lms531 firmware, lms511 firmware, lms500 firmware
Weakness
CWE-916
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.