CVE-2025-47276 Actualizer Uses OpenSSL’s “-passwd” Function Which Uses SHA512 Under The Hood Instead of Proper Password Hasher like Yescript/Argon2i

Vulnerability Details

Basic Information

Title CVE-2025-47276 Actualizer Uses OpenSSL’s “-passwd” Function Which Uses SHA512 Under The Hood Instead of Proper Password Hasher like Yescript/Argon2i
Type cve
Published 2025-05-13T15:34:28
Last Seen 2025-05-13T16:04:38
CVSS Score 7.5 (HIGH)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity LOW
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact HIGH
Availability Impact NONE

CVE Information

CVE IDs CVE-2025-47276
CWE CWE-328
Bulletin Family cve

Description

Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password…

Impact Assessment

Base Score 7.5
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.