« Volver al listado

CVE-2025-26486

Estado: AplazadaMedia (6)—

Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerabilities in Beta80 "Life 1st Identity Manager" enable an attacker with access to password hashes to bruteforce user passwords or find a collision to ultimately while attempting to gain access to a target application that uses "Life 1st Identity Manager" as a service for authentication. This issue affects Life 1st: 1.5.2.14234.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-26486",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-26486",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-19T18:28:07.501414Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
      "affectedData": [
        {
          "vendor": "Beta80",
          "product": "Life 1st",
          "versions": [
            {
              "status": "affected",
              "version": "1.5.2.14234"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-03-19T16:15:31.457",
  "references": [
    {
      "url": "https://euvd.enisa.europa.eu/vulnerability/CVE-2025-26486",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
    },
    {
      "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2025-26486",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
      "description": [
        {
          "lang": "en",
          "value": "CWE-327"
        },
        {
          "lang": "en",
          "value": "CWE-328"
        },
        {
          "lang": "en",
          "value": "CWE-760"
        },
        {
          "lang": "en",
          "value": "CWE-916"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Broken or Risky Cryptographic Algorithm, Use of Password Hash \nWith Insufficient Computational Effort, Use of Weak Hash, Use of a \nOne-Way Hash with a Predictable Salt vulnerabilities in Beta80 \"Life 1st Identity Manager\"\nenable an attacker with access to\npassword hashes\nto bruteforce user passwords or find a collision to ultimately while attempting to gain access to a target application that uses \"Life 1st Identity Manager\" as a service for authentication.\nThis issue affects Life 1st: 1.5.2.14234."
    },
    {
      "lang": "es",
      "value": "El uso de un algoritmo criptográfico roto o riesgoso, el uso de un hash de contraseña con un esfuerzo computacional insuficiente, el uso de un hash débil, el uso de un hash unidireccional con una vulnerabilidad de sal predecible en Beta80 Life 1st permite a un atacante usar la fuerza bruta de las contraseñas de los usuarios o encontrar una colisión para obtener acceso a una aplicación de destino que utiliza BETA80 \"Life 1st Identity Manager\" como un servicio para la autenticación. Este problema afecta a Life 1st: 1.5.2.14234."
    }
  ],
  "lastModified": "2026-06-17T09:01:54.057",
  "sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}