CVE-2023-3243

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/06/2023
Last modified:
02/08/2024

Description

<br /> ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash<br /> and utilize it to create new sessions. The hash is also a poorly salted MD5<br /> hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such<br /> as Alerton<br /> ACM.] Out of an abundance of caution, this CVE ID is being assigned to <br /> better serve our customers and ensure all who are still running this product understand <br /> that the product is end of life and should be removed or upgraded. <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:honeywell:alerton_bcm-web:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:alerton_bcm-web_firmware:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools