Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-37495

Опубликовано: 29 фев. 2024
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:*
Версия от 9.0 (включая) до 14.0 (исключая)

EPSS

Процентиль: 48%
0.00249
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.9
github
почти 2 года назад

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .

EPSS

Процентиль: 48%
0.00249
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-306