vendor:
Argus Surveillance DVR
by:
Salman Asad (@deathflash1411) a.k.a LeoBreaker
5.5
CVSS
MEDIUM
Weak Password Encryption
326
CWE
Product Name: Argus Surveillance DVR
Affected Version From: Argus Surveillance DVR 4.0
Affected Version To: Argus Surveillance DVR 4.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 x86 (Build 7601) & Windows 10
2021
Argus Surveillance DVR 4.0 – Weak Password Encryption
This exploit demonstrates weak password encryption in Argus Surveillance DVR 4.0. The author, Salman Asad (@deathflash1411), also known as LeoBreaker, provides a detailed description of the exploit and a guide on how to crack the password hash.
Mitigation:
To mitigate this vulnerability, the vendor should implement a stronger password encryption algorithm, such as bcrypt or Argon2. Users should also ensure they use strong passwords that are not easily guessable.