All versions of Econolite EOS traffic control software...
Moderate severity
Unreviewed
Published
Jan 26, 2023
to the GitHub Advisory Database
•
Updated Feb 15, 2023
Description
Published by the National Vulnerability Database
Jan 26, 2023
Published to the GitHub Advisory Database
Jan 26, 2023
Last updated
Feb 15, 2023
All versions of Econolite EOS traffic control software are vulnerable to CWE-328: Use of Weak Hash, and use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.
References