CVE-2023-0452
Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.10%
- CWE
- CWE-328
- Published
- 2023-01-26
- Last modified
- 2026-03-13
Affected products
- Econolite EOS
Weakness type
Related vulnerabilities
- CVE-2025-41652 — Weidmueller: Authentication Bypass Vulnerability in Industrial Ethernet Switches
- CVE-2025-27595 — Weak hashing alghrythm
- CVE-2024-54143 — openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection
- CVE-2023-46133 — crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
- CVE-2024-48847 — MD5 bypass operation
- CVE-2023-43635 — Vault Key Sealed With SHA1 PCRs
- CVE-2023-43630 — Config Partition Not Measured From 2 Fronts
- CVE-2026-32129 — Poseidon V1 variable-length input collision via implicit zero-padding