Vulnerabilities (CVE)

Filtered by CWE-836
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-62618 2025-10-31 N/A 8.0 HIGH
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and replay them or crack the password hash offline. In ELOG 3.1.5-20251014 release, HTML files are rendered as plain text.
CVE-2025-48925 1 Smarsh 1 Telemessage 2025-10-22 N/A 4.3 MEDIUM
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.
CVE-2025-52543 1 Copeland 8 E3 Supervisory Controller Firmware, Site Supervisor Bx 860-1240, Site Supervisor Bxe 860-1245 and 5 more 2025-10-01 N/A 7.5 HIGH
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.
CVE-2023-4299 1 Digi 39 Cm, Cm Firmware, Connect Es and 36 more 2024-11-21 N/A 9.0 CRITICAL
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.