CVE-2024-5743

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 13, 2025
CWE ID 916

Summary

CVE-2024-5743 is a newly disclosed vulnerability that affects Eve Play, a home automation software, up to version 1.1.42. An attacker can exploit the "Use of Password Hash With Insufficient Computational Effort" weakness to execute arbitrary code, potentially gaining unauthorized access to the system. The vulnerability arises from the software's failure to apply sufficient computational effort during the password verification process, allowing an attacker to use rainbow table attacks or brute force methods to crack the password. This issue poses a significant risk to users, and it is recommended that they update to the latest version of Eve Play as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share