CVE-2023-37495

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Feb 29, 2024

Summary

CVE-2023-37495 is a cybersecurity vulnerability affecting passwords stored in Person documents created using the "Add Person" action on the People & Groups tab in the Domino® Administrator. These passwords are secured using a cryptographically weak hash algorithm, making them susceptible to brute force attacks. An attacker who gains access to the hashed values could potentially determine user passwords. However, this issue does not impact Person documents created through user registration.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share