Use of a broken or risky cryptographic algorithm in Airspan Networks products - CVE-2022-21800
Published: February 4, 2022
Vulnerability identifier: #VU60304
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21800
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to the affected product uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. A remote authenticated attacker can crack the hashed passwords.
Affected software
MMP
PTMP C-series
PTMP A5x
PTP C-series
PTMP C-series
PTMP A5x
PTP C-series
How to mitigate CVE-2022-21800
Install updates from vendor's website.
MMP - addressed in versions 1.0.3, 1.0.4
PTMP C-series - addressed in versions 2.5.4.1, 2.9.0
PTMP A5x - addressed in versions 2.5.4.1, 2.9.0
PTP C-series - addressed in versions 2.8.6.1, 2.90
PTMP C-series - addressed in versions 2.5.4.1, 2.9.0
PTMP A5x - addressed in versions 2.5.4.1, 2.9.0
PTP C-series - addressed in versions 2.8.6.1, 2.90