Cryptographic issues in Centreon - CVE-2011-4432
Published: November 10, 2011 / Updated: August 11, 2020
Centreon
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.