CVE-2014-9251: Medium severity zenoss vulnerability
Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack on hash values in the database, aka ZEN-15413.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9251?
The severity of CVE-2014-9251 is moderate due to the weak password hashing algorithm that can lead to brute-force attacks.
How do I fix CVE-2014-9251?
To fix CVE-2014-9251, update to a version of Zenoss Core that improves password hashing, such as version 5.0.1 or later.
What systems are affected by CVE-2014-9251?
CVE-2014-9251 affects multiple versions of Zenoss Core, specifically versions up to and including 5 Beta 3.
What types of attacks can exploit CVE-2014-9251?
CVE-2014-9251 can be exploited through brute-force attacks targeting the weakly hashed passwords stored in the database.
Who can be impacted by CVE-2014-9251?
Organizations using Zenoss Core versions affected by CVE-2014-9251 are at risk of unauthorized access due to weak password protection.