CVE Vulnerabilities

CVE-2023-28084

Insufficiently Protected Credentials

Published: Apr 25, 2023 | Modified: Feb 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
OneviewHp*6.60.04 (excluding)
OneviewHp7.0 (including)8.2 (excluding)
Oneview_global_dashboardHpe*2.72 (excluding)

Potential Mitigations

References