Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts v
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAu
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack
FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins
Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom
The root password hash of the device can be obtained through unencrypted information in the firmware.
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor
Frequently Asked Questions
What is CWE-916?
CWE-916 (CWE-916) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-916?
There are 19 CVE records associated with CWE-916 in our database. Of these, 2 are critical severity, 4 are high severity, and 10 are medium severity.
How can I protect against CWE-916 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-916 using AI-powered security agents.
Detect CWE-916 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-916 vulnerabilities across your infrastructure.
Get Started