CVE-2021-36767
Published: 08 October 2021
Summary
CVE-2021-36767 is a critical-severity Use of Password Hash With Insufficient Computational Effort (CWE-916) vulnerability in Digi Realport. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 41.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2021-23355
Vulnerability details
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed version…
more
of the server's access password. The attacker may then crack this hash offline in order to successfully login to the server.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Information from security contacts highlights password hashing methods with insufficient computational effort, preventing their adoption.