search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Toshiba Global Commerce Solutions' 4690 Point of Sale operating system contains a password hashing algorithm that can be reversed

Vulnerability Note VU#622950

Original Release Date: 2014-04-21 | Last Revised: 2014-04-21

Overview

Toshiba Global Commerce Solutions' 4690 Point of Sale operating system contains a password hashing algorithm that can be reversed. (CWE-328)

Description

Toshiba Global Commerce Solutions' 4690 Point of Sale operating system contains a password hashing algorithm that can be reversed. (CWE-328) The ADXCRYPT algorithm that may be used for password hashing on the 4690 operating system is susceptible to known-plaintext attacks and hash collisions.

Additional details about this vulnerability may be found in Security Bulletin R1005054.

Impact

An attacker may be able to reverse or find a hashing collision for passwords hashed with ADXCRYPT and stored in the ADXCSOUF.DAT file.

Solution

Use "Enhanced Security"
4690 OS version V5R1 or later has the option to enable "Enhanced Security" that will use the SHA1 hashing algorithm. Instructions for enabling 4690 OS Enhanced Security can be found in the V6R4 4690 OS Planning, Installation, and Configuration Guide beginning on page 140.

Use a LDAP server for authentication
4690 OS version V6R3 or later has the option to use an LDAP server for authentication. This method will use whatever hashing algorithm the LDAP server uses. Instructions for enabling LDAP, or Directory Services, can be found in the V6R4 4690 OS Planning, Installation, and Configuration Guide beginning on page 23.

Vendor Information

622950
 

Toshiba Commerce Solutions Affected

Notified:  January 23, 2014 Updated: April 21, 2014

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 3 AV:L/AC:M/Au:S/C:P/I:P/A:N
Temporal 2.3 E:POC/RL:OF/RC:C
Environmental 1.8 CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Brian Kamusinga and David Odell for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

CVE IDs: CVE-2014-0361
Date Public: 2014-04-01
Date First Published: 2014-04-21
Date Last Updated: 2014-04-21 19:34 UTC
Document Revision: 15

Sponsored by CISA.