Insecure Encryption of One-Time Passwords Exposes DRYiCE Optibot Reset Station to Attack
CVE-2024-23580
6.5MEDIUM
What is CVE-2024-23580?
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
Affected Version(s)
DRYiCE Optibot Reset Station 1.0, 2.0