Use of a broken cryptographic algorithm affects HCL DRYiCE iAutomate
CVE-2023-23347

7.1HIGH

Key Information:

Vendor
CVE Published:
9 August 2023

What is CVE-2023-23347?

HCL DRYiCE iAutomate is susceptible to vulnerabilities related to the implementation of a flawed cryptographic algorithm. This weakness may enable attackers to gain unauthorized access to sensitive information, potentially jeopardizing both the confidentiality and integrity of critical data managed by the software. Businesses using this product should take immediate action to assess and mitigate potential risks associated with this vulnerability.

Affected Version(s)

HCL DRYiCE iAutomate 6..0, 6.1, 6.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.