CVE-2023-37482
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2023-37482 is a newly identified vulnerability affecting certain web servers. This issue arises from the login functionality that fails to normalize response times to login attempts, allowing an unauthenticated attacker to distinguish valid from invalid usernames via side-channel information. This could potentially allow attackers to perform credential stuffing attacks or brute force attacks, posing a serious risk to system security. Organizations using the affected web servers are urged to patch this vulnerability promptly. Failure to do so may expose user accounts to potential compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- DP
- Rly
- DC
- Simatic S7-PLCSIM Advanced
Affected Vendors
- DC Comics
- Siemens AG