02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: icscertCogent DataHub Use of Password Hash With Insufficient Computational Effort
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 0.69% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 50.1% of scored records. A rank, not a probability.
- NVD base score
- The NVD has published no score for this record
- NVD CVSS vector
- No NVD score to derive
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2014-05-30 23:00Z12 YR AGO
- Last updated
- 2025-10-03 16:34Z11 MO AGO
- Reserved
- 2014-03-13
- Assigning CNA
- icscert
- Record state
- PUBLISHED
- Severity
- Not rated by the issuing CNA
- CNA CVSS vector
- Not published by the issuing CNA
- Weaknesses
- CWE-916Use of Password Hash With Insufficient Computational EffortBase
- CWE-255
- Data version
- 5.1
- Document digest
- 9c6c18cd50cb0f53ff02112fff8b5b64d6cb847b16565ecd41db74a3a666ee06
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
SRC: CNA
Cogent Real-Time Systems, Inc. has produced a new version of the
Cogent DataHub application, Version 7.3.5, that fixes three of the four
identified vulnerabilities. The updated version is available at the
following address:
http://cogentdatahub.com/Download_Software.html
Cogent
has indicated that it will not be fixing the cryptographic weaknesses
of hashed usernames and passwords because of compatibility issues with
existing systems. Cogent and the researcher agree that an effective
mitigation strategy for users is to select sufficiently strong
passwords. Cogent has indicated that password hashes can be checked for
strength using sites such as: https://crackstation.net/ .