PT-2025-4486 · Optimizely · Episerver.Cms.Core
Published
2025-01-04
·
Updated
2025-01-06
·
CVE-2025-22390
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Optimizely EPiServer.CMS.Core versions prior to 12.32.0
Description
A medium-severity issue exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters, lacking adequate complexity to resist modern attack techniques such as password spraying or offline password cracking.
Recommendations
For versions prior to 12.32.0, update to version 12.32.0 or later to resolve the issue. As a temporary workaround, consider enforcing stronger password policies to minimize the risk of exploitation. Restrict access to password settings to minimize the risk of weak passwords being set. Avoid using weak passwords until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Episerver.Cms.Core