CVE-2023-37482

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 11, 2025
CWE ID 203

Summary

CVE-2023-37482 is a newly identified vulnerability affecting certain web servers. This issue arises from the login functionality that fails to normalize response times to login attempts, allowing an unauthenticated attacker to distinguish valid from invalid usernames via side-channel information. This could potentially allow attackers to perform credential stuffing attacks or brute force attacks, posing a serious risk to system security. Organizations using the affected web servers are urged to patch this vulnerability promptly. Failure to do so may expose user accounts to potential compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DP
  • Rly
  • DC
  • Simatic S7-PLCSIM Advanced

Affected Vendors

  • DC Comics
  • Siemens AG