CWE•Base•Incomplete•7 recent CVEs
CWE-836Use of Password Hash Instead of Password for Authentication
Description
The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.
[object Object]
Common consequences
- Access Control→Bypass Protection Mechanism,Gain Privileges or Assume IdentityAn attacker could bypass the authentication routine without knowing the original password.