CVE detail
CVE-2019-10855 — CVE-2019-10855
Published 2019-05-23 · Modified 2026-06-17 · Vendor computrols · Product computrols_building_automation_software · Source nvd
HIGH
severity
CVSS-derived band
0.0100
EPSS probability
exploitation probability, 30d
60.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References