Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-3243

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/06/2023
Última modificación:
02/08/2024

Descripción

*** Pendiente de traducción *** <br /> ** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash<br /> and utilize it to create new sessions. The hash is also a poorly salted MD5<br /> hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such<br /> as Alerton<br /> ACM.] Out of an abundance of caution, this CVE ID is being assigned to <br /> better serve our customers and ensure all who are still running this product understand <br /> that the product is end of life and should be removed or upgraded. <br /> <br />

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:h:honeywell:alerton_bcm-web:-:*:*:*:*:*:*:*
cpe:2.3:o:honeywell:alerton_bcm-web_firmware:-:*:*:*:*:*:*:*


Referencias a soluciones, herramientas e información