CVE-2012-2565: Medium severity bloxx web filtering vulnerability
Published Jun 9, 2012
·Updated
Bloxx Web Filtering before 5.0.14 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.
Affected Software
1 affected component
Bloxx Web Filtering<=5.0.13
Event History
Jun 9, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2565?
CVE-2012-2565 is considered to have a medium severity due to its potential for password compromise.
2
How do I fix CVE-2012-2565?
To fix CVE-2012-2565, upgrade to Bloxx Web Filtering version 5.0.14 or later.
3
Who is affected by CVE-2012-2565?
CVE-2012-2565 affects all versions of Bloxx Web Filtering prior to 5.0.14.
4
What type of attack is possible with CVE-2012-2565?
CVE-2012-2565 allows context-dependent attackers to use rainbow tables to potentially recover cleartext passwords.
5
What is the impact of CVE-2012-2565 on password security?
CVE-2012-2565 weakens password security by lacking a salt in the password hashing process, making it vulnerable to attacks.