PT-2024-19947 · Hcl · Hcl Dryice Optibot Reset Station

·

CVE-2024-23580

·

Published

2024-05-28

·

Updated

2024-07-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HCL DRYiCE Optibot Reset Station (affected versions not specified)
Description The issue concerns insecure encryption of One-Time Passwords (OTPs) in the HCL DRYiCE Optibot Reset Station. This could potentially allow an attacker with access to the database to recover some or all encrypted values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23580

Affected Products

Hcl Dryice Optibot Reset Station