CVE Published: 28/05/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: HCL |
Vendor: HCL Software |
Product: DRYiCE Optibot Reset Station Status : PUBLISHED
CVE-2024-23579 Description
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N