Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cogent DataHub Use of Password Hash With Insufficient Computational Effort | |
| Weaknesses | CWE-916 | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Status: PUBLISHED
Assigner: icscert
Published: 2014-05-30T23:00:00
Updated: 2025-10-03T16:34:03.154Z
Reserved: 2014-03-13T00:00:00
Link: CVE-2014-2354
No data.
Status : Deferred
Published: 2014-05-30T23:55:02.987
Modified: 2025-10-03T17:15:45.460
Link: CVE-2014-2354
No data.