Security Advisory

CVE-2020-10539

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-02-05 09:21:27
Last updated 2024-08-04 11:06:09
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user passwords MD5 hash stored in the database. It is also compared to a second MD5 hash, which is the same for every user (aka a "Backdoor Password" of 3p1kursupport). If the submitted password matches either one, access is granted.