CVE-2024-23580

HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
Configurations

No configuration.

History

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0113496 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0113496 -

03 Jul 2024, 01:47

Type Values Removed Values Added
CWE CWE-326

29 May 2024, 13:02

Type Values Removed Values Added
Summary
  • (es) HCL DRYiCE Optibot Reset Station se ve afectada por el cifrado inseguro de contraseñas de un solo uso (OTP). Esto podría permitir que un atacante con acceso a la base de datos recupere algunos o todos los valores cifrados.

28 May 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-28 22:15

Updated : 2024-11-21 08:57


NVD link : CVE-2024-23580

Mitre link : CVE-2024-23580

CVE.ORG link : CVE-2024-23580


JSON object : View

Products Affected

No product.

CWE
CWE-326

Inadequate Encryption Strength