← volver
CVE-2023-33243highCWE-916

CVE-2023-33243

41Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 8.1epss 4.4%
de la publicación al arma0 días
Publicada en NVD15 jun
1ª PoC26 may
probabilidad de explotación
4.4%top 10% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect users' passwords in case of a database compromise, this is rendered ineffective when allowing to authenticate using the password hash.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/a
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.