CVE-2023-3243
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/06/2023
Last modified:
02/08/2024
Description
<br />
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash<br />
and utilize it to create new sessions. The hash is also a poorly salted MD5<br />
hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such<br />
as Alerton<br />
ACM.] Out of an abundance of caution, this CVE ID is being assigned to <br />
better serve our customers and ensure all who are still running this product understand <br />
that the product is end of life and should be removed or upgraded. <br />
<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:h:honeywell:alerton_bcm-web:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:honeywell:alerton_bcm-web_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page