Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
History

Fri, 03 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
Title Cogent DataHub Use of Password Hash With Insufficient Computational Effort
Weaknesses CWE-916
References
Metrics cvssV2_0

{'score': 5.0, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N'}

cvssV2_0

{'score': 6, 'vector': 'AV:L/AC:H/Au:S/C:C/I:C/A:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2014-05-30T23:00:00

Updated: 2025-10-03T16:34:03.154Z

Reserved: 2014-03-13T00:00:00

Link: CVE-2014-2354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-05-30T23:55:02.987

Modified: 2025-10-03T17:15:45.460

Link: CVE-2014-2354

cve-icon Redhat

No data.